bola-idor - Broken Object Level Authorization (BOLA/IDOR) Testing
Identifies and tests Broken Object Level Authorization and Insecure Direct Object Reference vulnerabilities in APIs and web applications.
Tags
Updated: 2026-09-18Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Map object identifiers across applications
- Replay requests using alternate tokens
- Test unauthenticated endpoint access
- Test HTTP verb swaps and parameter pollution
- Test deprecated API versions
Inputs
- Target API endpoints and URLs
- User session tokens
- Resource object identifiers
Outputs
- Vulnerability test findings
- HTTP response comparison diffs
Requirements
- Claude Code environment
- Burp Suite with Autorize extension or curl
