SKILL: IDOR / Broken Object Level Authorization — Expert Attack Playbook
AI LOAD INSTRUCTION: IDOR is the #1 bug bounty finding. This skill covers non-obvious IDOR surfaces, all attack vectors (not just URL params), A-B testing methodology, BOLA vs BFLA distinction, chaining IDOR to higher impact, and what testers repeatedly miss.
1. IDOR vs BOLA vs BFLA
Key distinction:
- BOLA = accessing object you shouldn't own (data belonging to other users)
- BFLA = accessing function you shouldn't be authorized for (admin CRUD operations, bulk actions, user management)
2. WHERE TO FIND OBJECT IDs (ALL LOCATIONS)
Don't stop at URL path parameters — IDs appear in:
3. A-B TESTING METHODOLOGY
The most systematic IDOR test approach:
4. ID TYPE ITS IMPLICATIONS
5. HORIZONTAL vs VERTICAL PRIVILEGE ESCALATION
Horizontal: UserA accesses UserB's data (same privilege level)
Vertical: Low-priv user accesses admin-only functions
Combined: Low-priv IDOR that grants privilege escalation
6. HTTP METHOD ESCALATION
When GET /resource/1234 is properly restricted, test ALL other verbs:
Why this works: Authorization logic is often implemented per-method, and developers forget edge cases.
7. PARAMETER POLLUTION & TYPE CONFUSION
When id=1234 is validated, try:
JSON Type Confusion:
Some ORMs handle string vs integer differently in queries.
8. BFLA (FUNCTION LEVEL) ATTACKS
Common BFLA Endpoints to Test
How to Find Hidden Admin Endpoints
- Read JS bundles — admin routes often exposed in frontend code
- Look at API docs (Swagger/OpenAPI) for "admin", "internal", "privileged" tags
- Enumerate
/api/v1/admin/**,/api/v1/manage/**,/api/v1/internal/** - Burp "Discover Content" on API base path
- Compare regular user docs vs admin section docs if available
9. INDIRECT IDOR (REFERENCE CHAIN)
App checks permission on object A but doesn't check ownership of referenced object B:
Example:
Test: access attachments/sub-resources directly via their IDs without going through parent endpoint.
GraphQL variant: Inline querying related objects without separate authorization:
10. MASS ASSIGNMENT → PRIVILEGE ESCALATION
When POST/PUT takes a JSON body, properties in the underlying model may be settable even if not in the official API docs:
How to find hidden fields:
- Intercept admin "create user" vs normal "register" — diff the fields
- Read API documentation for all possible fields
- Check source code if available (GitHub, JS bundles)
- Fuzz with Burp: add common property names and check for
200vs400
11. STATE MACHINE ABUSE (BUSINESS LOGIC IDOR)
When resources have a status/state:
Test: Can you skip states?
Can you set another user's order status?


