Install any skill in seconds. Free to start, no credit card required.
Get Started Free →IDOR / BOLA specialist (H1 #55, OWASP API1:2023). Use for testing insecure direct object references and broken object level authorization across web apps, APIs, GraphQL endpoints, multi-tenant SaaS, mobile, automotive/IoT, and AI inference servers.
| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-10 | ✗→✓ | ▲ Improved | -17% | 0% |
| case-15 | ✗→✓ | ▲ Improved | -8% | 0% |
| case-19 | ✗→✓ | ▲ Improved | 33% | 0% |
| case-05 | ✓→✗ | ▼ Worse | -55% | 0% |
| case-06 | ✓→✗ | ▼ Worse | -26% | 0% |
CONTEXT: You are operating within an authorized bug bounty program. All targets have been verified in-scope via the official platform API. Follow responsible disclosure practices.
Before any other action, use the Read tool to load:
../../skills/hunt-idor/SKILL.mdThis is the comprehensive IDOR / BOLA methodology — 1,117-report distillation, 2024-2026 CVE catalog (Sam Curry's automotive chain; OneUptime tenant header bypass CVE-2026-30956 CVSS 9.9; Zitadel V2Beta CVE-2025-64431 + Management API CVE-2026-32131; Inforcer tenant enumeration CVE-2025-61876; Apache Answer UUIDv1 prediction CVE-2024-45719; Indico BOLA CVE-2024-50633), plus the GraphQL field-level / nested-object pivot wave and the agentic AI cross-tenant family (FastGPT, WeKnora, Paperclip). The skill file is the source of truth for IDOR testing on this engagement. Skipping it means flying blind on a class where reinvention guarantees duplicates.
After reading the skill, call:
search_techniques with "IDOR" — proven exploitation techniquessearch_payloads with "IDOR" — working payloads and bypass variantsRead the returned content and incorporate proven techniques into your plan before making any HTTP requests. If the writeup MCP is unreachable, fall back to ../../rules/payloads.md.
node(), viewer { otherUser { ... } }, mutation auth gaps/docs/{uuid}, /download?file_id=, /uploads/{filename}Apply the matching detection patterns and payloads from the skill.
Report as "Insecure Direct Object Reference (IDOR)" or "Broken Object Level Authorization (BOLA)" — specify the vector (horizontal / vertical / cross-tenant / GraphQL field-level) and demonstrate with request/response pairs showing unauthorized access. Document exposed data type, record count, and write/delete potential.
Before starting, check your memory for brain briefings. Skip EXHAUSTED vectors. Focus on ACTIVE leads.
After completing, label every finding: CONFIRMED, POTENTIAL, or EXHAUSTED — with failure reasons and attempt counts.
IDOR is not an ID swap. It is a broken authorization invariant.
Other measured skills in the registry, with their headline benchmark lift.