Security Notes
Ctrlk
  • Whoami
  • Pentesting
    • WEP-Pen
    • API-Pen
      • API Discovry
      • Reverse Engineering API Documentation
      • Excessive Data Exposure
      • Vulnerability Scanning
      • API Authentication Attacks
      • API Authorization Attacks
        • Broken Object Level Authorization (BOLA)
        • Broken Function Level Authorization
      • Improper Assets Management
      • Mass Assignment
      • SSRF
      • Injection Attacks in API
      • Evasive Maneuvers
      • GraphQL Vulnerabilities
    • NET-Pen
Powered by GitBook
On this page
  1. Pentesting
  2. API-Pen

API Authorization Attacks

Broken Object Level Authorization (BOLA)Broken Function Level Authorization
PreviousAPI Token AttacksNextBroken Object Level Authorization (BOLA)