Skip to content
#

bola

Here are 40 public repositories matching this topic...

BurpAPISecuritySuite

Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and automated reconnaissance. Supports REST/GraphQL/SOAP APIs with Nuclei, Turbo Intruder, and external tool integration. OWASP API Top 10 coverage.

  • Updated Jun 9, 2026
  • Python

Matrix-driven authorization testing for HTTP APIs and MCP tool-calls. Turns an access-control matrix into positive & negative tests that catch BOLA, BFLA, BOPLA, privilege escalation and authorization drift — with CWE/OWASP-tagged SARIF for CI/CD.

  • Updated Jul 10, 2026
  • Python

A modern, deliberately-vulnerable, API-first web app - a DVWA alternative covering the OWASP API Security Top 10 (2023) and Web Top 10 (2021). Two distinct origins (Next.js 14 + FastAPI) with a cookie-to-Bearer JWT bridge and 45+ catalogued vulns, each paired with a secured twin. Local, educational use only.

  • Updated Jul 13, 2026
  • TypeScript

Improve this page

Add a description, image, and links to the bola topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the bola topic, visit your repo's landing page and select "manage topics."

Learn more