Lab Portal
All URLs for the Akamai API Security demo environment · 172.236.213.192
Live Dashboards
Baseline Traffic Monitor
Live
https://traffic.security-lab.cloud
Continuous automated traffic across all 11 lab apps — full request & response, per-app stats, live feed.
Active Testing Monitor
Scan
https://scan.security-lab.cloud
Shows HTTP traffic from APISec Active Testing scans — baseline traffic auto-filtered, request body visible.
LLM Traffic Monitor
AI/Live
https://ai.security-lab.cloud/dashboard
Live feed of all AI API requests — clients, models, token counts, auth errors. APISec sensor active.
Attack Vector AI
Attack/Live
https://attack.security-lab.cloud
OWASP API Top 10 live demo — AI-driven attack against crAPI, all vulnerabilities visible in real time.
OWASP API Top 10 — Primary Target
crAPI — Completely Ridiculous API
https://crapi.security-lab.cloud
Main OWASP API Top 10 demo target. 3,000 baseline users, full vehicle/shop/community API. Vehicle registration, mechanic requests, community posts.
→
MailHog
https://mailhog.security-lab.cloud
Fake mail server for crAPI & Hoppscotch registrations. Use any address at signup — confirmation email and OTP appear here.
→
Workshop
Setup — start here
portal.security-lab.cloud/workshop/setup
Pick your participant number, import the Hoppscotch collection + environment in two clicks, then follow the attack walkthrough.
→
1 · Pre-Requisites
portal.security-lab.cloud/workshop/prework
What to check before the workshop starts — browser, access, credentials.
→
2 · Workshop Guide
portal.security-lab.cloud/workshop/guide
Full step-by-step follow-along: discovery, BOLA, AI API security, findings review.
→
Quick Reference
portal.security-lab.cloud/workshop/quick-reference
One-page cheat sheet: URLs, endpoints, environment variables.
→
Facilitator Guide DE
portal.security-lab.cloud/workshop/facilitator
German facilitator notes: server access, reset runbook, troubleshooting.
→
crAPI — Attack Target
crapi.security-lab.cloud
The main application under attack. Participants reach it through Hoppscotch — no direct login needed, accounts are pre-created (participantNN@workshop.lab).
→
Hoppscotch — API Client
hoppscotch.security-lab.cloud
The API client used for every request against crAPI. The bottom-right “🎓 Workshop Setup” button jumps back to the setup page.
→
MailHog optional
mailhog.security-lab.cloud
Only needed if someone registers a new account (OTP/confirmation lands here). Not required for the workshop — participant accounts already exist.
→
Live Attack Demo 🔒 password
portal.security-lab.cloud/workshop/demo
Presenter-driven 3-panel attack walkthrough. Protected by the demo password.
→
Reset Workshop 🔒 facilitators only
portal.security-lab.cloud/workshop/reset
Cleans participant data before a new event. Separate password — participants cannot run this. Dry-run preview, then apply.
→
REST & GraphQL APIs
VAmPI
REST
https://vampi.security-lab.cloud
Vulnerable API — BOLA, auth bypass, mass assignment, user enumeration.
DVRA Restaurant
REST
https://restaurant.security-lab.cloud
Damn Vulnerable RESTaurant API — 16 endpoints, OAuth2 auth, order & menu flows.
Mock LLM API
AI/LLM
https://ai.security-lab.cloud
OpenAI-compatible mock — /v1/chat/completions, /v1/embeddings, Bearer auth, 6 simulated AI clients.
DVGA
GraphQL
https://dvga.security-lab.cloud
Damn Vulnerable GraphQL API — introspection, injection, BOLA via GraphQL.
Pixi
REST
https://pixi.security-lab.cloud
OWASP DevSlop Pixi — JWT vulnerabilities, excessive data exposure, broken auth.
BankingWS
SOAP
https://soap.security-lab.cloud/ws
Vulnerable SOAP Banking API — BOLA, BFLA, Mass Assignment, Excessive Data Exposure. WSDL at /ws?wsdl.
UserService
gRPC
https://grpc.security-lab.cloud
Vulnerable gRPC User API — BOLA, BFLA, Mass Assignment, Excessive Data Exposure. JSON gateway /v1/* for APISec.
Web Application Targets
Juice Shop
OWASP
https://juiceshop.security-lab.cloud
OWASP Juice Shop — XSS, SQLi, broken auth, sensitive data exposure.
WebGoat
OWASP
https://webgoat.security-lab.cloud
OWASP WebGoat — interactive lessons for SQLi, IDOR, broken access control.
NodeGoat
Node.js
https://nodegoat.security-lab.cloud
OWASP NodeGoat — Node.js vulnerabilities, prototype pollution, SSJS injection.
RailsGoat
Rails
https://railsgoat.security-lab.cloud
OWASP RailsGoat — Ruby on Rails vulnerabilities, mass assignment, CSRF.
DVWA
PHP
https://dvwa.security-lab.cloud
Damn Vulnerable Web App — SQLi, XSS, file upload, command injection levels.
bWAPP
PHP
https://bwapp.security-lab.cloud
Buggy Web App — 100+ web vulnerabilities across OWASP Top 10 categories.
Altoro Mutual
Banking
https://altoro.security-lab.cloud
Vulnerable banking demo — XPath injection, XSS, broken session management.
Mutillidae II
PHP
https://mutillidae.security-lab.cloud
NOWASP Mutillidae — 40+ vulnerability types, multiple difficulty levels.