Live BOLA Hacking Demo

Опубликовано: 31 Май 2026
на канале: APIsec University
2,380
112

Live BOLA Hacking Demo: How to Test and Fix API Authorization Flaws (w/ Jesse Freeman from APIsec)

Watch this jam-packed, hands-on session with Jesse (Dean of Ambassadors at APIsec University) and Dan Barahona as they dive deep into Broken Object Level Authorization (BOLA)—the #1 OWASP API Security risk.

In this live webinar, Jesse walks through:
What BOLA is (and how it relates to IDOR)
Real-world examples from Duolingo, Venmo, and Trello
A live hacking demo against the vulnerable “Crappy” app using tools like Burp Suite
How attackers exploit excessive data exposure and UUID-based APIs
How to automate BOLA testing using APIsec’s platform
Why manual pen testing isn’t enough—and how to catch vulnerabilities before they hit production

🔧Tools used: Burp Suite, Postman, APIsec Scanner
🧠 Perfect for: AppSec engineers, penetration testers, bug bounty hunters, and security leaders who want to level up API testing
🎓 Learn more at: https://www.apisec.ai
💬 Join the Discord:   / discord  
👨‍💻 Try APIsec free: https://www.apisec.ai/products

⏱️ Timestamps:
0:00 - Intro to BOLA
5:20 - OWASP guidance & real-world hacks
12:45 - Live BOLA testing demo with Burp Suite
31:00 - Automating BOLA testing with APIsec
50:15 - Q&A and next steps