Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
310 commits
Select commit Hold shift + click to select a range
67c786b
Update notes.md
LinuxUser255 Apr 15, 2023
bc64f42
Update notes.md
LinuxUser255 Apr 15, 2023
03ff0d1
Update notes.md
LinuxUser255 Apr 15, 2023
e82195d
Update and rename notes.txt to notes.md
LinuxUser255 Apr 15, 2023
746c7be
Update notes.md
LinuxUser255 Apr 15, 2023
4380f13
Update notes.md
LinuxUser255 Apr 15, 2023
16b55fa
Update notes.md
LinuxUser255 Apr 15, 2023
e629ea5
Update notes.txt
LinuxUser255 Apr 15, 2023
88d10ea
Update notes.txt
LinuxUser255 Apr 15, 2023
8190638
Rename notes.txt to notes.md
LinuxUser255 Apr 15, 2023
ef893cd
Update notes.md
LinuxUser255 Apr 15, 2023
641de24
Update command-injection-lab-02.py
LinuxUser255 Apr 15, 2023
23cf156
Update and rename notes.txt to notes.md
LinuxUser255 Apr 15, 2023
e17e9bd
Update notes.md
LinuxUser255 Apr 15, 2023
5336218
Update notes.md
LinuxUser255 Apr 15, 2023
a58fe20
Update notes.md
LinuxUser255 Apr 15, 2023
597ce0f
Update command-injection-lab-03.py
LinuxUser255 Apr 15, 2023
04381f5
Update command-injection-lab-03.py
LinuxUser255 Apr 15, 2023
a0d0bf9
Create passwordcapture.html
LinuxUser255 May 11, 2023
e8bb7f2
Create cookie_stealer.html
LinuxUser255 May 11, 2023
7921da7
Create steal_php_cookies.php
LinuxUser255 May 11, 2023
44ed8c3
Create another_cookie_grabber.html
LinuxUser255 May 11, 2023
f0dffd6
Update README.md
LinuxUser255 May 17, 2023
180ab9b
Update notes.txt
LinuxUser255 May 17, 2023
07a5873
Update notes.txt
LinuxUser255 May 17, 2023
d471789
Update sqli-lab-03.py
LinuxUser255 May 17, 2023
f7a98f3
Create OAuth-account-hijacking-via-redirect_uri.html
LinuxUser255 May 17, 2023
8a38f04
Update notes.txt
LinuxUser255 Jun 9, 2023
62d6e7f
Update notes.txt
LinuxUser255 Jun 9, 2023
677708b
Update README.md
LinuxUser255 Jun 28, 2023
a9b387e
Merge branch 'rkhal101:main' into main
LinuxUser255 Jul 13, 2023
66adc3a
Update README.md
LinuxUser255 Jul 20, 2023
8527cbe
Merge branch 'rkhal101:main' into main
LinuxUser255 Jul 20, 2023
076100a
Update README.md
LinuxUser255 Jul 20, 2023
d3dc7d8
Update README.md
LinuxUser255 Jul 20, 2023
bd50db7
Update README.md
LinuxUser255 Jul 20, 2023
05b1b29
Update README.md
LinuxUser255 Jul 20, 2023
cff6d34
Update README.md
LinuxUser255 Jul 20, 2023
666f5c8
Update notes.txt
LinuxUser255 Jul 20, 2023
944746a
Merge branch 'rkhal101:main' into main
LinuxUser255 Jul 28, 2023
b1c2e4f
Update README.md
LinuxUser255 Jul 28, 2023
816477f
Merge branch 'rkhal101:main' into main
LinuxUser255 Aug 28, 2023
3da62ec
Update notes.txt
LinuxUser255 Sep 21, 2023
fb42c90
Update notes.txt
LinuxUser255 Sep 21, 2023
62229d3
Update README.md
LinuxUser255 Sep 26, 2023
3c4b55f
Update README.md
LinuxUser255 Sep 26, 2023
c729c91
Update README.md
LinuxUser255 Sep 26, 2023
db78f31
Update README.md
LinuxUser255 Sep 26, 2023
96aa700
Update README.md
LinuxUser255 Sep 26, 2023
572ce93
Update README.md
LinuxUser255 Sep 26, 2023
ec9d511
Update README.md
LinuxUser255 Sep 26, 2023
8454f89
Update README.md
LinuxUser255 Sep 28, 2023
49489be
Update README.md
LinuxUser255 Sep 29, 2023
b370f87
Update README.md
LinuxUser255 Oct 4, 2023
8b07834
Add files via upload
LinuxUser255 Oct 4, 2023
1e00495
Update README.md
LinuxUser255 Oct 5, 2023
d1b83c7
Create exploit.php
LinuxUser255 Oct 6, 2023
907ac4d
Update notes.md
LinuxUser255 Oct 6, 2023
538f9f6
Create Blind_SQLi_with_OutOfBandDataExfiltration.md
LinuxUser255 Oct 12, 2023
afe470c
Update and rename notes.txt to notes.xml
LinuxUser255 Oct 21, 2023
a3dbd3d
Update and rename notes.txt to notes.xml
LinuxUser255 Oct 21, 2023
22758ec
Create SQLi _with_Filter_Bypass_via_XML-encoding.xml
LinuxUser255 Oct 25, 2023
b01871b
Update and rename notes.txt to notes.md
LinuxUser255 Oct 25, 2023
4218ae8
Update notes.md
LinuxUser255 Oct 25, 2023
32a6e2c
Create Broken_Access_Control
LinuxUser255 Oct 25, 2023
992f4f4
Rename Broken_Access_Control to Misc
LinuxUser255 Oct 25, 2023
d9cca08
Rename notes.txt to notes.txt
LinuxUser255 Oct 25, 2023
c5024e1
Delete XSS/Lab_01 directory
LinuxUser255 Oct 25, 2023
dff48ae
Update and rename notes.txt to notes.txt
LinuxUser255 Oct 25, 2023
5c177e5
Delete Broken_Access_Control/lab_01 directory
LinuxUser255 Oct 25, 2023
7f50b4d
Update sqli-lab-08.py
LinuxUser255 Oct 25, 2023
85baefe
Update notes.txt
LinuxUser255 Oct 25, 2023
513536d
Create sqli-lab-exploit-explained.md
LinuxUser255 Oct 25, 2023
5716d32
Update sqli-lab-08.py
LinuxUser255 Oct 25, 2023
318c45b
Update notes.txt
LinuxUser255 Oct 25, 2023
e91ff8e
Add files via upload
LinuxUser255 Oct 26, 2023
24075ac
Update practitioner-level-labs.md
LinuxUser255 Oct 26, 2023
0baea11
Rename practioner-level-labs.md to practitioner-level-labs.md
LinuxUser255 Oct 26, 2023
9cb00ec
Update README.md
LinuxUser255 Oct 26, 2023
57c5a70
Update practitioner-level-labs.md
LinuxUser255 Oct 26, 2023
838ced5
Update README.md
LinuxUser255 Oct 27, 2023
26e7ecd
Update practitioner-level-labs.md
LinuxUser255 Oct 27, 2023
bc6ce8d
Update Blind_SQLi_with_OutOfBandDataExfiltration.md
LinuxUser255 Oct 28, 2023
03ba903
Create lab-01.md
LinuxUser255 Nov 8, 2023
c5831a9
Update lab-01.md
LinuxUser255 Nov 8, 2023
26c4687
Update lab-01.md
LinuxUser255 Nov 8, 2023
9872f1f
Update lab-01.md
LinuxUser255 Nov 8, 2023
a4f7d36
Create graphql-hacking-technique.md
LinuxUser255 Nov 9, 2023
bfcfb01
Update sqli-lab-01.py
LinuxUser255 Nov 11, 2023
8503e91
Update sqli-lab-01.py
LinuxUser255 Nov 11, 2023
0bc4847
Update sqli-lab-02.py
LinuxUser255 Nov 11, 2023
cc733c5
Create script_info.md
LinuxUser255 Nov 14, 2023
91dae2f
Create ExploitScriptInfo.md
LinuxUser255 Nov 14, 2023
208e7f3
Update script_info.md
LinuxUser255 Nov 14, 2023
782fe8a
Update sqli-lab-01.py
LinuxUser255 Nov 14, 2023
35652a6
Create main.py
LinuxUser255 Nov 15, 2023
f5b0e88
Update main.py
LinuxUser255 Nov 15, 2023
979d78a
Update main.py
LinuxUser255 Nov 15, 2023
b2adb54
Update xxe-injection-lab-01.py
LinuxUser255 Dec 5, 2023
2876feb
Update xxe-injection-lab-02.py
LinuxUser255 Dec 5, 2023
cdbabcc
Update xxe-injection-lab-07.py
LinuxUser255 Dec 5, 2023
1c03323
Update xxe-injection-lab-08.py
LinuxUser255 Dec 5, 2023
058b29c
Update xxe-injection-lab-08.py
LinuxUser255 Dec 5, 2023
d24bcea
Update xxe-injection-lab-09.py
LinuxUser255 Dec 5, 2023
2c9f617
Update xxe-injection-lab-01.py
LinuxUser255 Dec 5, 2023
4a3aa29
Update xxe-injection-lab-01.py
LinuxUser255 Dec 5, 2023
42e54d2
Update xxe-injection-lab-01.py
LinuxUser255 Dec 5, 2023
38accdb
Update xxe-injection-lab-02.py
LinuxUser255 Dec 5, 2023
dbfb140
Create XSS-Contexts.md
LinuxUser255 Jan 12, 2024
542ac78
Create DOM-Based-Vulns.md
LinuxUser255 Jan 12, 2024
9931b70
Update DOM-Based-Vulns.md
LinuxUser255 Jan 12, 2024
3d1787d
Update README.md
LinuxUser255 Jan 13, 2024
dc869f7
Update README.md
LinuxUser255 Jan 13, 2024
e950fa9
Update README.md
LinuxUser255 Jan 13, 2024
a01f217
Create notes.md
LinuxUser255 Jan 13, 2024
f5eab64
Update notes.md
LinuxUser255 Jan 13, 2024
2a455b8
Delete Insecure-Deserialization/lab-01/notes.md
LinuxUser255 Jan 13, 2024
812ab39
Create Insecure-Deserialization
LinuxUser255 Jan 13, 2024
099ecbf
Delete Insecure-Deserialization
LinuxUser255 Jan 13, 2024
2446f04
Create lab-01.md
LinuxUser255 Jan 13, 2024
92de5c7
Create lab-02.md
LinuxUser255 Jan 13, 2024
7456b02
Update and rename Misc to CheatSheet.md
LinuxUser255 Jan 15, 2024
8d715be
Update README.md
LinuxUser255 Jan 15, 2024
32ea5d7
Update README.md
LinuxUser255 Jan 24, 2024
d86f2cf
Rename CheatSheet.md to AExtraBurpSuiteStuff.md
LinuxUser255 Jan 24, 2024
51772f5
Rename AExtraBurpSuiteStuff.md to ExtraBurpSuiteStuff.md
LinuxUser255 Jan 24, 2024
557b170
Create links.md
LinuxUser255 Jan 24, 2024
b4f80a7
Update links.md
LinuxUser255 Jan 24, 2024
3e32554
Create ip-block-bruteforce.py
LinuxUser255 Jan 30, 2024
83cfe8a
Create system.php
LinuxUser255 Mar 8, 2024
6f7c8d8
Create lab-01.md
LinuxUser255 Mar 14, 2024
288ec2e
Create lab-01.md
LinuxUser255 Mar 21, 2024
7239177
Update lab-01.md
LinuxUser255 Mar 21, 2024
a8002a0
Update lab-01.md
LinuxUser255 Mar 21, 2024
2ff75c0
Update lab-01.md
LinuxUser255 Mar 21, 2024
f823762
Update lab-01.md
LinuxUser255 Mar 21, 2024
4db4bed
Update lab-01.md
LinuxUser255 Mar 21, 2024
d64b7e6
Create lab-02.md
LinuxUser255 Mar 21, 2024
ce7d62a
Update lab-02.md
LinuxUser255 Mar 21, 2024
d6880e4
Update lab-02.md
LinuxUser255 Mar 21, 2024
fe7a7e7
Create lab-07.md
LinuxUser255 Mar 21, 2024
879ff8d
Create lab-02.md
LinuxUser255 Mar 27, 2024
68fb348
Update README.md
LinuxUser255 Apr 2, 2024
247633a
Update lab-02.md
LinuxUser255 Apr 2, 2024
14ea8ad
Update main.py
LinuxUser255 Apr 9, 2024
3598ef5
Create API_Vulnerabilities.md
LinuxUser255 Apr 10, 2024
95bb87c
Update API_Vulnerabilities.md
LinuxUser255 Apr 10, 2024
0a7e7e6
Update API_Vulnerabilities.md
LinuxUser255 Apr 10, 2024
3ccac88
Update lab-02.md
LinuxUser255 Apr 10, 2024
feb4071
Create basic.py
LinuxUser255 Apr 10, 2024
9d24682
Create default.py
LinuxUser255 Apr 10, 2024
913cf61
Create specialWordlists.py
LinuxUser255 Apr 10, 2024
8b85bb0
Create request.txt
LinuxUser255 Apr 10, 2024
a483357
Create General_Info.md
LinuxUser255 Apr 11, 2024
5118449
Update General_Info.md
LinuxUser255 Apr 11, 2024
b76e13b
Update lab-01.md
LinuxUser255 Apr 11, 2024
4a417b5
Create lab-02.md
LinuxUser255 Apr 11, 2024
45f92a0
Update lab-02.md
LinuxUser255 Apr 11, 2024
96f2316
Update lab-02.md
LinuxUser255 Apr 11, 2024
02aa72f
Update lab-02.md
LinuxUser255 Apr 11, 2024
41431c3
Update main.py
LinuxUser255 Apr 25, 2024
a569e0a
Create lab-03.md
LinuxUser255 Apr 25, 2024
d369a66
Update lab-03.md
LinuxUser255 Apr 25, 2024
109621f
Update lab-03.md
LinuxUser255 Apr 25, 2024
16bdb7b
Update notes.md
LinuxUser255 Apr 25, 2024
c0a67b7
Create solution.md
LinuxUser255 Apr 26, 2024
eeca7ff
Update solution.md
LinuxUser255 Apr 26, 2024
717c535
Create about.md
LinuxUser255 Apr 27, 2024
6688d2d
Rename about.md to about-01.md
LinuxUser255 Apr 27, 2024
da0a168
Add files via upload
LinuxUser255 Apr 27, 2024
34abe17
Update SSTI.md
LinuxUser255 Apr 27, 2024
1c7ab73
Update about-01.md
LinuxUser255 Apr 27, 2024
94dd90f
Update SSTI.md
LinuxUser255 Apr 27, 2024
8c8c9f5
Update SSTI.md
LinuxUser255 Apr 27, 2024
523814c
Update SSTI.md
LinuxUser255 Apr 27, 2024
8fc1ee1
Update SSTI.md
LinuxUser255 Apr 27, 2024
5de9ebc
Create lab-01.md
LinuxUser255 Apr 27, 2024
68b526d
Update lab-01.md
LinuxUser255 Apr 27, 2024
180a292
Create lab-02.md
LinuxUser255 Apr 28, 2024
68e948d
Create urlencode.sh
LinuxUser255 May 14, 2024
6262096
Create urlencode.c
LinuxUser255 May 14, 2024
02862e5
Create urlencode.go
LinuxUser255 May 14, 2024
eabed9e
Create urlencode.rs
LinuxUser255 May 14, 2024
bafd5c8
Create urlencode.java
LinuxUser255 May 14, 2024
5c68980
Create urlencode.js
LinuxUser255 May 14, 2024
a7503cd
Create urlencode.py
LinuxUser255 May 14, 2024
c45a728
Update README.md
LinuxUser255 Jun 7, 2024
3721c16
Update README.md
LinuxUser255 Jun 7, 2024
856b839
Update lab-02.md
LinuxUser255 Jun 8, 2024
7e76951
Create delcarlos.md
LinuxUser255 Jun 8, 2024
9a4d595
Create lab_03.md
LinuxUser255 Jun 11, 2024
97fabc5
Update XSS-Contexts.md
LinuxUser255 Jun 11, 2024
d050493
Create Checklist.md
LinuxUser255 Jun 23, 2024
4d7bc6e
Create WebAppHackers_Checklist.md
LinuxUser255 Jun 23, 2024
4e8b661
Update XSS-Contexts.md
LinuxUser255 Jun 23, 2024
8545046
Update links.md
LinuxUser255 Sep 7, 2024
35178f4
Create CL-TE.py
LinuxUser255 Sep 10, 2024
3b8e708
Create TE-CL.py
LinuxUser255 Sep 10, 2024
df134e5
Create H2-TE.py
LinuxUser255 Sep 10, 2024
e79acfb
Create H2-Tunnel.py
LinuxUser255 Sep 10, 2024
1a6d25d
Create auth.php
LinuxUser255 Sep 11, 2024
1de6bdc
Create notes-on-phpfile.txt
LinuxUser255 Sep 11, 2024
70d8804
Create main.js
LinuxUser255 Sep 11, 2024
0c67c39
Create GoBuster.md
LinuxUser255 Sep 11, 2024
1084e03
Create crAPI-NotesAndChallenges.md
LinuxUser255 Sep 12, 2024
1528b00
Update crAPI-NotesAndChallenges.md
LinuxUser255 Sep 12, 2024
be75f22
Update crAPI-NotesAndChallenges.md
LinuxUser255 Sep 12, 2024
5f6fb9f
Update notes.md
LinuxUser255 Oct 16, 2024
c7a8bf9
Update notes.md
LinuxUser255 Oct 16, 2024
d1be1b1
Update notes.md
LinuxUser255 Oct 16, 2024
7a9a79d
Update notes.md
LinuxUser255 Oct 16, 2024
aa155a9
Update notes.md
LinuxUser255 Oct 16, 2024
01deb1b
Create solution.md
LinuxUser255 Oct 16, 2024
d8144b1
Create llm-01.md
LinuxUser255 Nov 5, 2024
fa14ea0
Create webappvulnhints.txt
LinuxUser255 Dec 5, 2024
31e4a14
Create payloads.txt
LinuxUser255 Dec 5, 2024
2c6026d
Create SAML.md
LinuxUser255 Dec 14, 2024
323bcad
Create about.md
LinuxUser255 Dec 14, 2024
dfbd86a
Create session-persist.md
LinuxUser255 Dec 14, 2024
77eb056
Create open-redir.md
LinuxUser255 Dec 14, 2024
bc09f00
Create second-order-sqli.md
LinuxUser255 Dec 14, 2024
ce56914
Create LDAPi.md
LinuxUser255 Dec 14, 2024
3c69089
Update SAML.md
LinuxUser255 Dec 14, 2024
7222e6c
Create xxe-about.md
LinuxUser255 Dec 14, 2024
a152d56
Update cors-lab-01.html
LinuxUser255 Dec 18, 2024
7a8140c
Rename cors-lab-01.html to cors-lab-01.js
LinuxUser255 Dec 18, 2024
0ca7dbe
Rename cors-lab-01.js to cors-lab-01.html
LinuxUser255 Dec 18, 2024
b9df95a
Update cors-lab-01.html
LinuxUser255 Dec 18, 2024
61535a9
Create explained.md
LinuxUser255 Dec 18, 2024
cc6b933
Update notes.txt
LinuxUser255 Dec 18, 2024
b7b47d9
Delete cors/lab-01/cors-lab-01.html
LinuxUser255 Dec 18, 2024
c7cbb31
Create exploit-code.html
LinuxUser255 Dec 18, 2024
4d73d3f
Update about-cors.md
LinuxUser255 Dec 19, 2024
884cb9e
Create lfi-vs-path-traversal.md
LinuxUser255 Dec 19, 2024
dc9f722
Create payloads-explained.md
LinuxUser255 Dec 19, 2024
9c82b76
Create csrf-vs-cors.md
LinuxUser255 Dec 19, 2024
e5caf6c
Create xml-xxe-about.md
LinuxUser255 Dec 19, 2024
41bc83d
Create about-saml.md
LinuxUser255 Dec 19, 2024
ebe0f83
Create cd-cd-automating-security-testing.md
LinuxUser255 Dec 19, 2024
e133bb0
Update crAPI-NotesAndChallenges.md
LinuxUser255 Feb 11, 2025
5052c30
Update crAPI-NotesAndChallenges.md
LinuxUser255 Feb 11, 2025
7412f5e
Update ssrf-lab-01.py
LinuxUser255 Mar 27, 2025
e1d0725
created RCE material
LinuxUser255 Jan 24, 2026
96d05e3
created a sqli testing reference guide
LinuxUser255 Jan 24, 2026
2be1e68
edited main.py and organized files
LinuxUser255 Jan 24, 2026
d7d8453
edited the README title formatting
LinuxUser255 Jan 24, 2026
1b2f25c
created a markdown doc of the lab notes
LinuxUser255 Jan 24, 2026
ed21df5
updated stored XSS payloads
LinuxUser255 Feb 3, 2026
931da9a
updated web app hacking checklist
LinuxUser255 Apr 17, 2026
9cfca8d
chore: remove xss scripts, ignore .idea directory
LinuxUser255 Apr 28, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .gitignore
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
.idea/
94 changes: 94 additions & 0 deletions API/API_Vulnerabilities.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,94 @@
# [OWASP API Security Top Ten - 2023](https://owasp.org/API-Security/editions/2023/en/0x00-header/)

# Mass Assignment Attacks

## [Mass Assignment: OWASP](https://owasp.org/API-Security/editions/2019/en/0xa6-mass-assignment/)


### Mass Assignment vulnerabilities are present when an attacker is able to overwrite object properties that they should not be able to.
A few things need to be in play for this to happen. An API must have requests that accept user input, these requests must be able to alter values not available to the user,
and the API must be missing security controls that would otherwise prevent the user input from altering data objects.
The classic example of a mass assignment is when an attacker is able to add parameters to the user registration process that escalate their account from a basic user to an administrator.
The user registration request may contain key-values for username, email address, and password.
An attacker could intercept this request and add parameters like "isadmin": "true".
If the data object has a corresponding value and the API provider does not sanitize the attacker's input then there is a chance that the attacker could register their own admin account.

### Finding Mass Assignment Vulnerabilities

One of the ways that you can discover mass assignment vulnerabilities by finding interesting parameters in API documentation and then adding those parameters to requests.
Look for parameters involved in user account properties, critical functions, and administrative actions.

Additionally, make sure to use the API as it was designed so that you can study the parameters that are used by the API provider.
Doing this will help you understand the names and spelling conventions of the parameters that your target uses.
If you find parameters used in some requests, you may be able to leverage those in your mass assignment attacks in other requests. 

You can also test for mass assignment blind by fuzzing parameter values within requests.
Mass assignment attacks like this will be necessary when your target API does not have documentation available.
Essentially, you will need to capture requests that accept user input and use tools to brute force potential parameters.
I recommend starting out your search for mass assignment vulnerabilities by testing your target's account registration process if there is one.
Account registration is normally one of the first components of an API that accept user input.
Once registration has been tested then you will need to target other requests that accept user input.


The challenge with mass assignment attacks is that there is very little consistency in the parameters used between API providers.
That being said, if the API provider has some method for, say, designating accounts as administrators, they may also have some convention for creating or updating variables to make a user an administrator. 
Fuzzing can speed up your search for mass assignment vulnerabilities, but unless you understand your target’s variables, this technique can be a shot in the dark.

## You can use [Param Miner](https://portswigger.net/bappstore/17d2949a985c4b7ca092728dba871943) to fuzz for Mass Assignment
**See the [Documentation](https://github.com/nikitastupin/param-miner-doc) for additional explanation.**

 <br>

# Broken Object Level Authorization(BOLA)
## This is number One on [OWASP Top 10 API Security Risks – 2023](https://owasp.org/API-Security/editions/2023/en/0xa1-broken-object-level-authorization/)

When authorization controls are lacking or missing, UserA will be able to request UserB’s (along with many other) resources. APIs use values, such as names or numbers, to identify various objects. When we discover these object IDs, we should test to see if we can interact with the resources of other users when unauthenticated or authenticated as a different user. The first step toward exploiting BOLA is to seek out the requests that are the most likely candidates for authorization weaknesses. 

 When hunting for BOLA there are three ingredients needed for successful exploitation.

1. Resource ID: a resource identifier will be the value used to specify a unique resource. This could be as simple as a number, but will often be more complicated.
2. Requests that access resources. In order to test if you can access another user's resource, you will need to know the requests that are necessary to obtain resources that your account should not be authorized to access.
3. Missing or flawed access controls. In order to exploit this weakness, the API provider must not have access controls in place. This may seem obvious, but just because resource IDs are predictable, does not mean there is an authorization vulnerability present.

The third item on the list is something that must be tested, while the first two are things that we can seek out in API documentation and within a collection of requests. Once you have the combination of these three ingredients then you should be able to exploit BOLA and gain unauthorized access to resources. 

 <br>

## Finding Resource IDs and Request

You can test for authorization weaknesses by understanding how an API’s resources are structured and then attempting to access resources you shouldn’t be able to access. By detecting patterns within API paths and parameters, you might be able to predict other potential resources. The bold resource IDs in the following API requests should catch your attention:

```
GET /api/resource/1
GET /user/account/find?user_id=15
POST /company/account/Apple/balance
POST /admin/pwreset/account/90
```


In these instances, you can probably guess other potential resources, like the following, by altering the bold values:

```
GET /api/resource/**3**
GET /user/account/find?user_id=**23**
POST /company/account/**Google**/balance
POST /admin/pwreset/account/**111**
```

In these simple examples, you’ve performed an attack by merely replacing the bold items with other numbers or words. If you can successfully access the information you shouldn’t be authorized to access, you have discovered an authorization vulnerability.

 <br>

# Broken Function Level Authorization  
## This is number 5 on [OWASP Top 10 API Security Risks – 2023](https://owasp.org/API-Security/editions/2023/en/0xa5-broken-function-level-authorization/)
### BFLA is performing unauthorized actions

Where BOLA is all about accessing resources that do not belong to you, BFLA is all about performing unauthorized actions. BFLA vulnerabilities are common for requests that perform actions of other users. These requests could be lateral actions or escalated actions. Lateral actions are requests that perform actions of users that are the same role or privilege level. Escalated actions are requests that perform actions that are of an escalated role like an administrator. The main difference between hunting for BFLA is that you are looking for functional requests. This means that you will be testing for various HTTP methods, seeking out actions of other users that you should not be able to perform.

If you think of this in terms of a social media platform, an API consumer should be able to delete their own profile picture, but they should not be able to delete other users' profile pictures. The average user should be able to create or delete their own account, but they likely shouldn't be able to perform administrative actions for other user accounts. For BFLA we will be hunting for very similar requests to BOLA.

1. Resource ID: a resource identifier will be the value used to specify a unique resource. 
2. Requests that perform authorized actions. In order to test if you can access another update, delete, or otherwise alter other the resources of other users.
3. Missing or flawed access controls. In order to exploit this weakness, the API provider must not have access controls in place. 

Notice that the hunt for BFLA looks familiar, the main difference is that we will be seeking out functional requests. When we are thinking of CRUD (create, read, update, and delete), BFLA will mainly concern requests that are used to update, delete, and create resources that we should not be authorized to. For APIs that means that we should scrutinize requests that utilize POST, PUT, DELETE, and potentially GET with parameters.  We will need to search through the API documentation and/or collection for requests that involve altering the resources of other users. So, if we can find requests that create, update, and delete resources specified by a resource ID then we will be on the right track. If the API you are attacking includes administrative requests or even separate admin documentation, then those will be key to see if you are able to successfully request those admin actions as a non-admin user. 
Loading