Secure APIs

SQL Injection Vulnerabilities you own this product

This project is part of the liveProject series Secure APIs from Web Application Attacks
intermediate Java • Postman for API testing • basic debugging
skills learned
identifying implementation vulnerabilities • remediating Java code vulnerabilities • testing functionality with Postman
Sashank Dara
1 week · 6-8 hours per week · BEGINNER

pro $24.99 per month

  • access to all Manning books, MEAPs, liveVideos, liveProjects, and audiobooks!
  • choose one free eBook per month to keep
  • exclusive 50% discount on all purchases

lite $19.99 per month

  • access to all Manning books, including MEAPs!


5, 10 or 20 seats+ for your team - learn more

Look inside
In this liveProject, you’ll patch SQL injection vulnerabilities in your company’s bus ticket API. SQL injection is one of the most common ways of attacking a web application, and your challenges will include investigating this code-level vulnerability and applying a fix in the Java code. You’ll get experience using Postman to test your API’s functionality before and after applying your fix.

This liveProject was implemented by Natan Streppel.
This project is designed for learning purposes and is not a complete, production-ready application or solution.

book resources

When you start your liveProject, you get full access to the following books for 90 days.

project author

Sashank Dara

Sashank Dara received his PhD in cybersecurity from IIIT-Bangalore in the area of applied cryptography and threat intelligence. He’s an expert cybersecurity technologist with more than 17 years of experience in the field, including as a consultant advisor for Manipal Global Education Services’ cybersecurity programs and as a security technology and strategy advisor for security startups including Appknox, Haltdos, and He remains a trusted information security consultant and advisor for top companies in EdTech, IT/ITes, academia, and real estate. He’s the co-inventor of 5 U.S. patents (and 3 IETF drafts) in the areas of cloud, SDN, and NFV security, and he’s published more than a dozen research papers at IEEE, LNCS conferences in the areas of cloud security, privacy, cryptography, and threat intelligence. A prolific speaker at security conferences and invited talks, Dara is currently the CTO and co-founder of Seconize, an award-winning cybersecurity startup pioneering a cyber risk and compliance management SaaS product suite.


he liveProject is for Java programmers familiar with basic REST API development. To begin this project you will need to be familiar with:

  • Intermediate level Java (classes, objects)
  • Basics of Spark (GET and POST handlers)
  • Basics of SQL and JDBC (how to read SQL and perform queries)
  • Basics of Linux and performing commands from the command line
  • Java IDEs such as Eclipse or IntelliJ IDEA
  • Testing APIs, using Postman
  • Gradle
  • Docker
  • GIT
  • Basic Debugging
  • Code Reviews
  • Code Refactoring
  • Unit Testing

you will learn

In this series of liveProjects, you’ll learn how to spot common code-level vulnerabilities, along with fixes and verification methods.

  • Setting up the environment to run a reference API implementation using Java Spring
  • Testing the functionality of a reference API implementation using Postman
  • Identifying the implementation vulnerabilities
  • Fixing Java code to remediate vulnerabilities
  • Retesting code for functionality using Postman


You choose the schedule and decide how much time to invest as you build your project.
Project roadmap
Each project is divided into several achievable steps.
Get Help
While within the liveProject platform, get help from other participants and our expert mentors.
Compare with others
For each step, compare your deliverable to the solutions by the author and other participants.
book resources
Get full access to select books for 90 days. Permanent access to excerpts from Manning products are also included, as well as references to other resources.

choose your plan


only $41.67 per month
  • five seats for your team
  • access to all Manning books, MEAPs, liveVideos, liveProjects, and audiobooks!
  • choose another free product every time you renew
  • choose twelve free products per year
  • exclusive 50% discount on all purchases
  • SQL Injection Vulnerabilities project for free