Testing for BOLA with Burp Suite: a repeatable workflow
A step-by-step workflow for finding object-level authorization flaws in APIs using an intercepting proxy and two authenticated sessions.
Tag
Articles tagged bola.
A step-by-step workflow for finding object-level authorization flaws in APIs using an intercepting proxy and two authenticated sessions.
A clear introduction to Broken Object Level Authorization (BOLA), why it tops the OWASP API Security list, how it happens, and how to reason about it.
IDOR and BOLA describe closely related authorization failures. This piece clarifies the terminology and when each label is the more precise one.