🚀 Join us for 30days of daily API security tests. #30days30tests We've spent last 120days building amazing API security tests for the community. Next 30 days we will post test tutorials here.
-
Updated
May 22, 2023
🚀 Join us for 30days of daily API security tests. #30days30tests We've spent last 120days building amazing API security tests for the community. Next 30 days we will post test tutorials here.
Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and automated reconnaissance. Supports REST/GraphQL/SOAP APIs with Nuclei, Turbo Intruder, and external tool integration. OWASP API Top 10 coverage.
API security testing framework for REST, GraphQL, and gRPC that validates authorization logic using role-based testing and YAML-driven templates
Community generated list of API security tests to find OWASP top10, HackerOne top 10 vulnerabilities
Recon & vuln analysis from Burp Suite exports — IDORs, host injection, reset flows & payloads
Local-first security recon that briefs your AI coding agent: facts + tailored probes, code-in / artifacts-out. No LLM, no server, no running app.
Authorization contract testing for IDOR/BOLA in CI
Broken Object Level Authorization (BOLA) combined with credentialed CORS misconfiguration enables cross-user, cross-origin authenticated document exfiltration.
Matrix-driven authorization testing for HTTP APIs and MCP tool-calls. Turns an access-control matrix into positive & negative tests that catch BOLA, BFLA, BOPLA, privilege escalation and authorization drift — with CWE/OWASP-tagged SARIF for CI/CD.
Broken Object Level Authorization (BOLA) enables cross-user document viewing, modification, and unauthorized deletion via direct object reference.
Disclosure-safe IDOR/BOLA case study covering authorized access-control testing methodology, evidence handling, and remediation.
API security lab demonstrating Broken Object Level Authorization (IDOR/BOLA) and proper authorization enforcement.
A modern, deliberately-vulnerable, API-first web app - a DVWA alternative covering the OWASP API Security Top 10 (2023) and Web Top 10 (2021). Two distinct origins (Next.js 14 + FastAPI) with a cookie-to-Bearer JWT bridge and 45+ catalogued vulns, each paired with a secured twin. Local, educational use only.
CLI scanner that finds IDOR & BOLA vulnerabilities by testing object references in web APIs.
Black-box scanner for the OWASP API Security Top 10 (2023). Engineering diploma project, Vistula University in Warsaw, 2026.
Autonomous API Warfare & DevSecOps Orchestration Platform — AI-driven BOLA/IDOR vulnerability detection with MITRE ATT&CK mapping, CVSS v4.0 scoring, and FAIR financial telemetry
Automated Penetration Testing CLI Tool — 18 security testing modules, GraphQL schema leakage detection, SPA false positive filtering, CVSS v3.1 scoring, vulnerability chaining engine. Built for bug bounty hunters and offensive security testers.
Add a description, image, and links to the bola topic page so that developers can more easily learn about it.
To associate your repository with the bola topic, visit your repo's landing page and select "manage topics."