🏦 Acme Pay — payments API

Origin app, intentionally vulnerable. Served on pod payments-api-6c5466b765-wfk6f.

The same origin sits behind two hostnames so you can see a WAF's effect: open (no WAF) vs secure (wslproxy WAF, block mode).

Classic web (OWASP)

Named CVEs & SSRF (beyond the Top 10)

API security