High-performance vulnerability engine for modern repos. Automate the hunt for API leaks, BOLA, and logic flaws. Build secure, audit early, trust nothing.
-
Updated
May 9, 2026 - JavaScript
High-performance vulnerability engine for modern repos. Automate the hunt for API leaks, BOLA, and logic flaws. Build secure, audit early, trust nothing.
Hands-on CTF-style Broken Access Control lab for Node/Express, covering IDOR, vertical privilege escalation, JWT abuse, batch authorization bypass, and multi-tenant isolation.
CLI scanner that finds IDOR & BOLA vulnerabilities by testing object references in web APIs.
A hands-on web application penetration testing lab based on OWASP Juice Shop, covering the OWASP Top 10 vulnerabilities. Includes practical testing methodology, Burp Suite workflows, vulnerability analysis, CVSS scoring, and professional reporting.
Advanced automated IDOR testing tool with UUID fuzzing, JWT analysis, GraphQL support, POST request fuzzing, and smart ID parameter discovery.
Automated web security testing tool designed to detect Insecure Direct Object References (IDOR) vulnerabilities in web applications
Burp Suite extension for automated multi-tenant IDOR/BOLA testing
Official write-up for the E-Bazaar spotlight challenge from ISSessions FantasyCTF 2026. Covers IDOR, business logic bypasses, and insecure cookie manipulation.
To associate your repository with the idor-exploitation topic, visit your repo's landing page and select "manage topics."