Skip to content
Sedat Özdemir

Posts on bola

5 posts on bola. Notes from public sources and my own test lab.

Beyond IDOR: Logic Flaws and Invisible Doors in the API World

A deep dive into BOLA (Broken Object Level Authorization) and why modern security is no longer just about firewalls, but about the logic within our endpoints.

June 27, 2026·4 dk readapi-securitybolabug-bounty

Invisible Doors: The 'Help Yourself Without Asking' Logic in the API World

Hacking has evolved from simple SQL Injections to complex logic flaws. In this post, we dive into BOLA (Broken Object Level Authorization), the sneaky vulnerability that often bypasses automated scanners and how to spot it before the bad guys do.

June 15, 2026·4 dk readapisecuritybolaidor

Leaving the API Doors Unlocked: Did You Really Think a JWT Was Enough?

Have you ever felt that cold sweat down your neck when you realize your API is serving your entire database to the internet? Let's talk about the most common 'invisible' vulnerability: BOLA.

May 21, 2026·4 dk readapi-securitybolacybersecurity

The Keyless Lock of Invisible Doors: Why 'IDOR' is Just the Tip of the Iceberg in Modern API Security

A deep dive into the shift from monoliths to microservices and how logic flaws like BOLA have become the new frontier for Red Team operations.

May 5, 2026·4 dk readapisecuritybolaidor

JSON’s Backdoor: The Forgotten 'Logic' and Invisible Threats in API Security

Modern security isn't just about blocking scripts; it's about understanding the logic of your APIs. Let's dive into why WAFs aren't enough when your business logic is broken.

April 28, 2026·3 dk readapi-securitybolacybersecurity