Coder Social home page Coder Social logo

arunsathiya / akto Goto Github PK

View Code? Open in Web Editor NEW

This project forked from akto-api-security/akto

0.0 0.0 0.0 208.15 MB

Proactive, Open source API security → API discovery, Testing in CI/CD, Test Library with 150+ Tests, Add custom tests, Sensitive data exposure

Home Page: https://www.akto.io/

License: MIT License

JavaScript 23.34% C 0.03% Java 56.39% CSS 0.40% Vue 19.76% Dockerfile 0.04% Sass 0.02%

akto's Introduction


Akto.io API Security

Contributors

What is Akto?

How it worksGetting-StartedAPI InventoryAPI testingAdd TestJoin Discord community

Akto is an instant, open source API security platform that takes only 60 secs to get started. Akto is used by security teams to maintain a continuous inventory of APIs, test APIs for vulnerabilities and find runtime issues. Akto offers coverage for all OWASP top 10 and HackerOne Top 10 categories including BOLA, authentication, SSRF, XSS, security configurations, etc. Akto's powerful testing engine runs variety of business logic tests by reading traffic data to understand API traffic pattern leading to reduced false positives. Akto can integrate with multiple traffic sources - burpsuite, AWS, postman, GCP, gateways, etc. Here is our public roadmap for this quarter.

Akto enables security and engineering teams to secure their APIs by doing three things:

  1. API inventory
  2. Run business logic tests in CI/CD
  3. Find vulnerabilities in run-time
Akto.demo.mp4

How it works?

Step 1: Create inventory

Step 2: Run tests

How to get Started?

Using docker-compose (works for any machine which has Docker installed)

Run the following commands to install Akto. You'll need to have curl and Docker installed in order to run the container..

  1. Clone the Akto repo by using this command git clone https://github.com/akto-api-security/akto.git
  2. Go to the cloned directory cd akto
  3. Run docker-compose up -d

If you are setting this up in your own Cloud (AWS/GCP/Heroku), read this section

Please ensure the following for good security practices

  1. Open inbound security rule for port 9090 only. And restrict the source CIDR to VPC CIDR or your IP only.

  2. Use an EC2 from a private subnet -

    a. This way, no one will be able to make an inbound request to your machine.

    b. Ensure this private subnet has access to Internet so that outbound calls can succeed!

    c. You might have to set up tunneling to access instance via VPN using ssh -i pemfile ec2-user@vpn-public-instance -L 9090:private-instance:9090

    d. In your browser, visit http://private-instance:9090

  3. Use an EC2 from a public subnet - please don't! If you still want to do this, you can skip 2.b and 2.c. Simply access your instance via http://ip:9090

Akto is really powerful in Cloud deployment if you can provide your application's mirrored traffic (0 performance impact). You would also be able to schedule tests in CI/CD and invite more team members on the dashboard. For that, you should install Akto Enterprise edition available here. Read more about it here

API Security testing tutorials

Title Link
Introduction https://www.youtube.com/watch?v=oFt4OVmfE2s
Tutorial 1: SSRF Port Scanning (OWASP API7:2023) https://www.youtube.com/watch?v=WjNNh6asAD0

Develop and contribute

Quicksetup using VSCode Devcontainers

Prerequisites:

  1. Install VSCode
  2. Install VSCode Dev Containers extension
  3. Windows: Docker Desktop 2.0+ on Windows 10 Pro/Enterprise. Windows 10 Home (2004+) requires Docker Desktop 2.3+ and the WSL 2 back-end.
  4. macOSDocker Desktop 2.0+.
  5. LinuxDocker CE/EE 18.06+ and Docker Compose 1.21+.

Note: If using Docker Desktop, consider changing the memory allocation to 8 GB for better performance

Steps:

Clone repo and open in vscode

  1. Open terminal
  2. mkdir ~/akto_code
  3. cd ~/akto_code
  4. git clone https://github.com/akto-api-security/akto
  5. Open in VScode: code akto

Start Dev Container

  1. Go to View > Command Palette and type: Dev Containers: Reopen in Container
  2. Wait for the Dev Container to set up.
  3. Open localhost:9090 in your web browser to see the Akto dashboard

Manual Setup Instructions

Prerequisites

OpenJDK 8, node(v18.7.0+ link), npm(v8.15.0+), maven (v3.6.3 link), MongoDB (v5.0.3+ link)

Clone repo

  1. mkdir ~/akto_code
  2. cd akto_code
  3. git clone https://github.com/akto-api-security/akto

Setup database

  1. Open a new terminal tab
  2. cd ~
  3. mkdir ~/akto_mongo_data
  4. <path_to_mongo_folder>/bin/mongod --dbpath ~/akto_mongo_data

Setup Frontend

  1. Open a new terminal tab
  2. cd ~/akto_code/akto
  3. cd apps/dashboard
  4. npm install
  5. npm run hot

Setup Dashboard

  1. Open a new terminal tab
  2. cd ~/akto_code/akto
  3. export AKTO_MONGO_CONN="mongodb://localhost:27017"
  4. export DASHBOARD_MODE="local_deploy"
  5. mvn clean install
  6. mvn --projects :dashboard --also-make jetty:run -Djetty.port=9090

Setup Testing

  1. Open a new terminal tab
  2. cd ~/akto_code/akto
  3. cd apps/testing
  4. export AKTO_MONGO_CONN="mongodb://localhost:27017"
  5. mvn compile; mvn exec:java -Dexec.mainClass="com.akto.testing.Main"

Using Testing CLI tool

Run the following command to run testing CLI tool

docker run -v ./:/out  \ # needed to generate test report on host machine
    -e TEST_IDS='JWT_NONE_ALGO REMOVE_TOKENS' \ # space separated test ids
    -e AKTO_DASHBOARD_URL='<AKTO_DASHBOARD_URL>' \ 
    -e AKTO_API_KEY='<AKTO_API_KEY>' \ 
    -e API_COLLECTION_ID='123' \ # api collection id on which you want to run tests
    -e TEST_APIS='https://demo.com/api/books https://demo.com/api/cars' \ # space separated apis from the api collection on which you want to run tests. If not present, all apis in the collection will be tested. [optional]
    -e OVERRIDE_APP_URL='https://dummy.com' \ # If you want to test on a separate host. [optional] 
    aktosecurity/akto-api-testing-cli

Play around

  1. Open localhost:9090 in your favourite browser
  2. You will need to signup when logging in for the first time, next time onwards you can login

Debug

1. To debug front end, install Vue.js Chrome extension from [here](https://devtools.vuejs.org/guide/installation.html). 2. To debug backend, run the following before running web server - a. Set MAVEN_OPTS variable to enable debugging on your Java process
    export MAVEN_OPTS="-Xdebug -Xrunjdwp:transport=dt_socket,server=y,suspend=n,address=8081, -Dcom.sun.management.jmxremote=true -Dcom.sun.management.jmxremote.port=9010 -Dcom.sun.management.jmxremote.rmi.port=9010 -Dcom.sun.management.jmxremote.local.only=false -Dcom.sun.management.jmxremote.authenticate=false -Dcom.sun.management.jmxremote.ssl=false"

b. In Visual Studio code, click on any line number to set a breakpoint.

c. Attach the Java debugger from Run and Debug mode. If you are doing this for the first time, click on “Create launch.json file” and then “Add configuration”. Choose “Java: Attach process by ID” and save the file.
img1
d. A list of running Java processes with show up. Select the web server process to attach the debugger

Hits

Contributing

We welcome contributions to this project. Please read our CONTRIBUTING.md for more information on how to get involved.

License

This project is licensed under the MIT License.

akto's People

Contributors

ankush-jain-akto avatar shivam-rawat-akto avatar avneesh-akto avatar notshivansh avatar ayushaga14 avatar ark2307 avatar aktoboy avatar oren-akto avatar bhavik-dand avatar ankita28g avatar marksowell avatar mayankesh-akto avatar rishav1919 avatar dependabot[bot] avatar arjun-akto avatar thespeedx avatar arunsathiya avatar prixix avatar adarsh-jha-dev avatar jittojoyes98 avatar lud1161 avatar rajaryan18 avatar sandeepsrinivasan avatar anish-akto avatar siddoinghisjob avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.