Technical requirements
To illustrate how to exploit API vulnerabilities, we’ll be using two different intentionally vulnerable APIs. The BreachMe API can be installed by following the directions provided in its repository: https://github.com/PacktPublishing/API-Security-for-White-Hat-Hackers/tree/main/BreachMe-API. The crAPI API can be found at https://github.com/OWASP/crAPI.