IDOR Forge is an advanced and versatile tool designed to detect Insecure Direct Object Reference (IDOR) vulnerabilities in web applications.
-
Updated
Sep 25, 2025 - Python
IDOR Forge is an advanced and versatile tool designed to detect Insecure Direct Object Reference (IDOR) vulnerabilities in web applications.
✅ Experience the power of an automated Insecure Direct Object Reference (IDOR) vulnerability detection tool. Safeguard your applications with cutting-edge technology that identifies potential security weaknesses in an efficient and streamlined manner.
This repo contains different variants of Bug Bounty & Security & Pentest & Tech related Articles
Simplify penetration testing by generating realistic wordlists as needed ( e.g API keys, UUIDs, tokens, OrderId, transaction IDs, invoices, coupon codes) for brute-force and IDOR testing.
A lightweight, high-performance browser extension (Manifest V3) designed for penetration testers and ethical hackers. Features passive HTTP traffic inspection, automated IDOR/BOLA scoring, noise filtering, and AI-driven vulnerability analysis with PDF report generation. Built for ethical security research.
Hands-on CTF-style Broken Access Control lab for Node/Express, covering IDOR, vertical privilege escalation, JWT abuse, batch authorization bypass, and multi-tenant isolation.
Immerse yourself in a practical hacking exercise to gain valuable experience with prevalent security exploits. Explore six key vulnerabilities, including SQL injection, session hijacking, username enumeration, IDOR, XSS, and CSRF, for a comprehensive cybersecurity learning experience.
Disclosure-safe IDOR/BOLA case study covering authorized access-control testing methodology, evidence handling, and remediation.
Advanced automated IDOR testing tool with UUID fuzzing, JWT analysis, GraphQL support, POST request fuzzing, and smart ID parameter discovery.
A beta test for a multi target attack with a multi payload type.
This repository details an IDOR vulnerability in AbsysNet 2.3.1, which allows a remote attacker to brute-force session IDs via the /cgi-bin/ocap/ endpoint. Successful exploitation can compromise active user sessions, exposing authentication tokens in HTML. The attack is limited to active sessions and is terminated if the user logs out.
AI hybrid red teaming lab demonstrating how traditional web vulnerabilities (IDOR) can be chained with LLM behavior to expose sensitive data in modern applications.
A hands-on web application penetration testing lab based on OWASP Juice Shop, covering the OWASP Top 10 vulnerabilities. Includes practical testing methodology, Burp Suite workflows, vulnerability analysis, CVSS scoring, and professional reporting.
Hotel Booking Web Application Security Testing using OWASP ZAP | Demonstrates XSS, IDOR, Open Redirect vulnerabilities and their secure mitigations using React and Flask.
Achieve the concept of security of web coding through this project.
cyber security lab exam
Labs from the Hacktify Cybersecurity (HCS) - Penetration Testing Internship 2025
🎓 Complete IDOR (Insecure Direct Object Reference) Guide: Beginner → Advanced
Simulate API attack patterns (BOLA, credential stuffing, shadow APIs, rate spikes) against your own dev/staging endpoints to verify your defenses.
Add a description, image, and links to the idor-attack topic page so that developers can more easily learn about it.
To associate your repository with the idor-attack topic, visit your repo's landing page and select "manage topics."