testing-api-for-broken-object-level-authorization - Test APIs for BOLA and IDOR vulnerabilities
Tests REST and GraphQL APIs for unauthorized access or modification of other users’ resources by manipulating object identifiers.
Tags
Updated: 2026-10-01Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Enumerate API endpoints
- Map object identifiers
- Capture authenticated requests
- Test cross-user access
- Test cross-user modification
- Test cross-user deletion
- Test identifier manipulation
- Detect authorization bypasses
Inputs
- Target API endpoints and scope
- Written testing authorization
- Test user accounts
- Authentication tokens
- API documentation
- Intercepted API traffic
Outputs
- BOLA vulnerability findings
- HTTP response observations
- Authorization test results
- Console test output
Requirements
- Burp Suite Professional or OWASP ZAP
- Python 3.10 or later
- Python requests library
- Autorize Burp extension
- Explicit API owner permission
