Idor Hunter

Systematic IDOR/BOLA detection methodology recon, multi-account testing, bypass techniques, and report structure. Trigger when the user asks to test authorization controls or object-level access restrictions, wants to hunt for IDOR or BOLA on an API or web app, needs a structured methodology for multi-account access testing, is doing a bug bounty or pentest and wants to maximize IDOR coverage, or asks if they can access another user's data or whether authorization is enforced server-side.

Rifteo Updated

File contents

Rifteo/skills/tree/main/idor-hunter commit fb63b6f8e9

Frequently asked questions

npx skillmds@latest add rifteo/idor-hunter