Idor

Advanced IDOR/BOLA testing methodology for bug bounty and application security work. Use when testing or reviewing insecure direct object references, broken object-level authorization, cross-tenant access, account/member takeover through object IDs, payment/order/billing data exposure, destructive object mutations, GraphQL object authorization flaws, private file or export access, support/ticket/message/event authorization issues, or HTTP/API traffic with object identifiers in URL paths, query strings, JSON/form/multipart bodies, GraphQL variables, headers, cookies, mobile APIs, internal APIs, hidden features, and second-order workflows.

yafet-dev Updated

File contents

yafet-dev/bugbounty-codex-skills/tree/main/bug-type-skills/idor commit ce978f93e9

Frequently asked questions

npx skillmds@latest add yafet-dev/idor