Lab API · checkout
- ClassThe server trusted a value the browser sent
- EvidenceThe request field, and the lab order that followed
- ImpactWho is affected, inside the lab only
- FixThe server must set that value itself
Penetration testing here means a report a developer can use: one lab API request, one weakness class, and the fix. If your BCA, BTech, or IT labs stopped at theory, we practise that report with you. At Computer Education And Cybernetics (CEC) a mentor reads it before it counts. The lab is ~2 minutes from Maninagar Railway Station.
Or reach us directly
+91 75740 10176 · info@cecyours.org
A remediation report, four lines
Lab API · checkout
You read one request on a lab API, name the one weakness class the result belongs to, and write the fix. We give you that API and a written scope before the proxy opens.
Web and API penetration testing means authorised testing of an application you were given: you read one request, show what the server trusted, map that result to one weakness class, and write a remediation report a developer can apply. The OWASP Top 10 is the public list those classes come from. A proxy such as Burp Suite is how you see the request. Computer Education And Cybernetics (CEC) teaches this on lab APIs and does not assign tests on public websites.
A web API is a page’s way of asking the server to do something, such as place an order. The message has a path and a few fields. Penetration testing on an API starts when you can point at one field and say whether the server should have trusted it.
A web-testing proxy such as Burp Suite shows the request the lab app really sent. You read it. A paid Pro licence is not required to learn that, and we do not promise to supply one. The lab is the reading and the report, not a tour of buttons.
The OWASP Top 10 is a public list of the weakness classes most often found in web applications. Your report names the one class this finding belongs to. Listing all ten without a lab result is not a test.
A remediation report tells a developer what to change. You write the endpoint, the field, what the lab did, and the fix. A classmate who builds APIs should be able to apply the fix without repeating your test.
A task on paper first
Open one lab checkout request and circle the field the server should have decided itself. That circle is the line the report must explain, before you name a weakness class.
The test is allowed because the shop API is ours. The skill is the paragraph a developer can apply.
You are allowed to test one lab shop API, and only its checkout. The written scope names that API. Anything else is out.
Checkout sends an item and a price the page filled in. In the proxy you can see both. The catalogue price for that item is a different number from the one in a second lab request.
The server stored the order at the price in the request. It did not look up its own price. You stop. You do not try the same request on a live store, a college portal, or any API you were not given.
You name the checkout path, the price field, that the lab order total followed the request, and the fix: the server must set the price from its catalogue. You label the class in plain words: the design let the browser decide a value the server should decide. You do not attach a recipe for repeating the test.
An honest limit: this lab makes you accurate on one API and one class. Testing live companies, or working through every class on the public list, comes later and only with permission. Confirming a single web-page finding, before a full report, is the Maninagar ethical hacking lab. Scope and method for a whole engagement sit on the Ahmedabad penetration testing page.
Two changes are already in this work. You still write the fix from the request you saved, including when an assistant drafted the first paragraph. We ask you to point at that request, not at the draft.
The same lab request now comes back with a ready-made fix, a severity, and sometimes a second finding you never showed. The draft grew. The request you saved did not.
Login is less often a long-lived cookie and more often a token that expires. The server still has to check that the token belongs to the caller. A new token format does not remove that check.
Where an assistant still fails you
Web and API testing is shifting as assistants draft remediation text and as logins move to short-lived tokens. The durable skill is showing one field the server trusted and writing a fix a developer can apply. CEC trains that paragraph in the lab. A generated severity does not replace it.
About 80% of our training is practical. A mentor reads the report the way a reviewer would: Does the fix match the request, and did you stay on the lab API?
BCA, BTech, and IT students often arrive with theory and no request they have read. Career changers who already build or support software start from the field they already know. School learners of any grade start with counseling before a course. After 12th anyone can apply, from any stream.
You stay on an API we control. A mentor sends the report back when the fix is vague, when a weakness class is named without evidence, or when the test left the written scope.
You read one checkout request, record what the server trusted, and write the fix a developer can apply. Across our centres we have conducted 20,000+ of training. This hour is that paragraph, not a list of tool menus.
You can ask it to phrase the fix. You then delete any sentence you cannot point to in the request, the lab order, or the class you actually showed.
Computer Education And Cybernetics (CEC) teaches this API report inside the Cyber Security and Ethical Hacking with AI course. You start with counseling, read one lab request, name one weakness class, and leave with a remediation paragraph a mentor can recheck. We stay with you until you get a job, based on your performance.
This lab is part of our Cyber Security & Ethical Hacking with AI course, not a separate product. The Ahmedabad penetration testing page describes the wider method.
The remediation report is the proof you can show. We help you put it in a portfolio, then we stay with you for the job search.
How we stay with you
More detail on placement support at CEC.
These four names are enough to label a first lab. You write one of them only when the request showed it. BCA, BTech, and IT students use the label to connect a syllabus term to a fix. Career changers use the same paragraph to show they can explain a change, not only find a fault.
One account can open a record that belongs to someone else. You name this only when the lab showed that record.
The server treats something you typed as a command. You describe what was treated as a command. You do not paste a sample command into the report.
A missing or mismatched login token is accepted. The evidence is the request that should have been rejected.
The browser is allowed to set a value the server should set, such as a price. That is the class for the checkout lab.
CEC Maninagar is ~2 minutes from Maninagar Railway Station, on the 2nd floor of Gopal Tower. BRTS, AMTS both serve this side of the city. Visiting is optional — counseling by phone comes first.
Gopal Tower
2nd floor, Gopal Tower, Computer Education And Cybernetics, near Maninagar Railway Station Road, Maninagar, Ahmedabad, Gujarat 380008. Call +91 75740 10176 before you travel so we can confirm the day.
Learners also come from


Nayan Nathani
Software Faculty · 2+ years
Teaches Data Analytics and Cyber Security. In this lab, the review is whether the fix matches the request you saved and whether you stayed on the lab API.
This lab is at Maninagar. Nikol and Vatva are available when counseling places you there. Visiting any centre is optional.
~2 minutes from Maninagar Railway Station
2nd floor, Gopal Tower, Computer Education And Cybernetics, near Maninagar Railway Station Road, Maninagar, Ahmedabad, Gujarat 380008+91 75740 10176Near / opposite New DMart, Nikol (Satyam Plaza)
S -25/26, D-mart, Satyam Plaza, Raspan Cross Rd, opp. Suketu Residency, near Nikol, Ankur Chokadi, New India Colony, Nikol, Ahmedabad, Gujarat 382350+91 91049 37871Near Vatva Lake Garden; opposite Kashiben Hospital
1st Floor, Computer Education And Cybernetics, Opposite Kashiben Hospital Beside Khodiayar Vav, Near Vatva Lake Garden, Vinzol Crossing Rd, Deriya Para, Vatva, Ahmedabad, Gujarat 382440+91 91571 90839If your course named security and never showed you a request, bring that to counseling.
You test only an application programming interface you were given, on a lab app Computer Education And Cybernetics (CEC) controls. You read one request in a proxy, decide whether the server trusted a field it should have checked, and write a remediation report: the evidence, one weakness class, and the fix. You do not move on to a second target.
It is a short note a developer can use. It names the lab endpoint, the field the server trusted, what the lab did as a result, the weakness class in plain words, and the change the server should make. A list of tool names is not a report. The report is finished when someone else could apply the fix without repeating your test.
It is a public list of the weakness classes most often found in web applications, such as broken access control, injection, authentication failures, and insecure design. You attach one class to a finding you actually showed. Naming all ten without evidence is not the lab.
No. You need to read the request a lab app sends. We use a web-testing proxy such as Burp Suite for that. A paid Pro licence is not required, and we do not promise to provide one.
No. Labs use APIs CEC controls. A college portal, a public website, or a shop you were not given is out of scope, including when an assistant suggests it.
Assistants already draft remediation text, sometimes with a finding you did not show. Login is also shifting toward short-lived tokens. The work that stays valuable is checking that the server still decides the sensitive value, and writing only the fix you can point to in the request.
You read one lab checkout request, name one weakness class, and rewrite the fix until a mentor can follow it. About 80% of training time is practical. Counseling decides whether you start with the request itself or with how an API message is shaped. The practice sits inside our Cyber Security and Ethical Hacking with AI course.
If your labs stopped at theory, counseling starts you on one lab API and a report, not on a list of tool names. Career changers who already write or support software use the same report. You do not need a prior testing background. You do need to write the fix in words a developer can apply.
CEC Maninagar is ~2 minutes from Maninagar Railway Station, on the 2nd floor of Gopal Tower. BRTS, AMTS both serve the area. Learners also come from Kankaria, Isanpur, Ghodasar, Khokhra, Meghaninagar, Danilimda. The centre is at 2nd floor, Gopal Tower, Computer Education And Cybernetics, near Maninagar Railway Station Road, Maninagar, Ahmedabad, Gujarat 380008. Call +91 75740 10176 before you visit.
Yes. Counseling is by call, WhatsApp, or email on +91 75740 10176 or info@cecyours.org. Visiting the lab is optional. If another Ahmedabad centre is easier, say so in counseling and we will place you where the same practice fits.
Tell us whether you are in BCA, BTech, IT, or changing into this work. We will start you on the request or on foundations — and the lab stays on APIs we own.