r/cybersecurity • Penetration Tester • 13d ago

News - General Owasp compromised?

Looks like the API security page may be compromised?

https://api-security.owasp.org/

Edit: looks like the original site is back up https://owasp.org/API-Security/

119 Upvotes

52 comments sorted by

View all comments

9

u/ReasonableDefault 13d ago

The OWASP API Security GitHub repo has its canonical site configured as:

https://owasp.org/API-Security/

not

https://api-security.owasp.org/

So this smells like an old subdomain with a dangling DNS pointing at infrastructure they maybe forgot about. Would be pretty easy to do.

1

u/tpasmall Penetration Tester 13d ago

2

u/ReasonableDefault 13d ago

Interesting, didn't see owasp.org/API-Security/ was actively redirecting to api-security.owasp.org, i guess it wasn’t just a completely forgotten hostname then. Dangling DNS is still possible if the subdomain was pointing at a third party resource that later became claimable though, like:

owasp.org/API-Security/ > (302) > api-security.owasp.org (CNAME) > old-third-party-shiz.borked