API Security — Broken Object Level Authorization: Attack and Defense

What is OWASP?

The 2019 API Security Guidelines:

Broken Object Level Authorization:

The Scenario:

The API Endpoint:

GET https://mysecretproducts.io/products/37128
product id

The Problem:

The Attack:

Burp Suite — Intruder — Sniper Mode

The Mitigation:

The Prevention:


A software engineer by profession. Tinkers with electronics as a hobby. Loves literature and music. Likes to write and build things from scratch.

