Web & API security
Broken Access Control: Why IDOR and BOLA Top Every List
Why broken access control is the number one web risk in OWASP data, how IDOR and BOLA flaws lead to real breaches, why scanners miss them, and how to fix them.
· 6 min read
// API Pentest
Testing of REST and GraphQL APIs for broken object-level authorization, auth flaws, mass assignment and data over-exposure.
APIs now carry most of the data in a modern application, and most of the serious findings. Mobile apps, single-page front-ends and partner integrations all talk to the same endpoints, and a single missing authorization check exposes every record behind it.
An API penetration test works through your endpoints methodically, as each type of caller, against the OWASP API Security Top 10, and reports exactly which requests break which rules.
Read the full testing methodology.
// Process
A short call to agree targets, test type, dates and rules of engagement. You get a quote for that scope, then written authorization is signed before any testing starts.
Hands-on, tool-assisted testing aligned to OWASP and PTES, with every finding verified. Anything critical is reported to you immediately, not saved for the report.
A clear report: executive summary, then every finding with severity, evidence, reproduction steps and a specific fix. Followed by a readout call.
Once fixes are in, we verify each one and issue an updated report and an attestation letter you can share with customers and auditors.
// FAQ
API documentation (OpenAPI/Swagger spec or a Postman collection), credentials for each role, and a test environment. Without documentation the test still works, but more time goes into mapping the API.
Yes. GraphQL has its own failure modes (introspection exposure, batching attacks, and authorization enforced per resolver), which are covered alongside the usual API checks.
If your web app is a front-end for the same API, testing them together is usually cheaper than two separate engagements. We’ll scope it as one.
// Further reading
Web & API security
Why broken access control is the number one web risk in OWASP data, how IDOR and BOLA flaws lead to real breaches, why scanners miss them, and how to fix them.
· 6 min read
Web & API security
Seven JSON Web Token mistakes that let attackers forge or reuse tokens, from alg none and key confusion to weak secrets, and the RFC 8725 fixes.
· 5 min read
Penetration testing
A section-by-section guide to pentest reports (executive summary, scope, severity ratings, findings and retests) and how to turn one into a fix plan.
· 5 min read
// Also available
An authenticated test of your web application against the OWASP Top 10 and the business-logic flaws scanners never find.
External testing of everything you expose to the internet, and internal testing of what an attacker could reach once inside.
A fast, affordable baseline: automated scanning across your estate with every result validated, so you get a list of real issues, not 400 pages of noise.