Maintenance in progress: we are indexing a large batch of new skills. Some pages may load slowly or briefly show no results. Nothing is lost, and everything is back to normal within the hour.

Broken Object Level Authorization

Identify and exploit Broken Object Level Authorization (BOLA), historically known as Insecure Direct Object Reference (IDOR), in API architectures. Extremely common and critical flaw where an API fails to validate whether the currently authenticated user actually owns or retains permissions over the specifically requested database resource (ID).

ShulkwiSEC 3197bb6 3 files · 16.8 KB Updated 21 repo stars

File contents

ShulkwiSEC/bb-huge/tree/main/skills/curated/broken-object-level-authorization commit 3197bb6cfd

Frequently asked questions

npx skillmds add shulkwisec/broken-object-level-authorization