๐Ÿงช WAF Efficacy Lab โ€” fire every WAF rule (GET & POST) at this host and watch, live, what the WAF blocks. Open the lab โ†’

๐Ÿฆ Acme Pay โ€” payments API

Origin app, intentionally vulnerable. Served on pod payments-api-7b9ccbfbd6-cf66f.

The same origin sits behind two hostnames so you can see a WAF's effect: open (no WAF) vs secure (wslproxy WAF, block mode).

Classic web (OWASP)

Named CVEs & SSRF (beyond the Top 10)

API security