Broken Object-Level Authorization (BOLA / IDOR): the API bug we find most

A BOLA vulnerability (also called IDOR) is the single bug we report most often on API tests. Here is how we hunt it by swapping object IDs across two accounts, and how to shut it down with server-side authorization.
Read more
How a Series-B Fintech Closed 23 Critical API Flaws Before Their Next Raise

A Series-B fintech booked an API penetration test six weeks before due diligence. We found 23 critical issues, most of them authorization flaws no scanner would ever catch. Here is how the engagement actually ran.
Read more









