Skip to content
← LibraryTechnique entry
W-BOLAPrivilege Escalation

Broken Object Level Authorization (API BOLA)

OWASP API #1 — same as IDOR but on REST/GraphQL APIs; check every resource ID against the requester.

§ Where this technique fits

W-BOLA is catalogued under the Privilege Escalation tactic of the offensive-security kill-chain. It appears in 2 approved dossiers in the registry, typically at step 5.5 on average.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    Exfiltration Over C2 Channel
    T1041 · Exfiltration
    seen 1×