Updated
BOLA testing: verify object ownership in APIs
Learn how to assess broken object level authorization with two test accounts, ownership controls, and evidence that distinguishes a real access failure.
Security guides
Practical guides to application security checks, what a result establishes, and which limits belong in the report. Choose a topic that matches the decision you need to make.
Preparing a test? Start with scope and inventory. Investigating a candidate? Use the relevant API, browser, or identity guide to identify controls and collect narrowly scoped evidence. Reviewing a result? Read the reporting and retesting guides before treating a finding count as assurance.
Each guide includes a direct answer, specific assessment steps, limitations, FAQs, and links to primary technical sources. Active checks belong on targets you are authorized to assess, using the owner's intended policy and dedicated test fixtures.
Updated
Learn how to assess broken object level authorization with two test accounts, ownership controls, and evidence that distinguishes a real access failure.
Updated
Review URL importers, webhooks, and preview features for server-side request forgery using controlled destinations and clear network boundaries.
Updated
Assess GraphQL resolver permissions, field exposure, mutations, and query resource controls with known test data and bounded requests.
Updated
Turn an OpenAPI document into an assessment inventory, verify security declarations against runtime behavior, and record undocumented coverage gaps.
Updated
Evaluate API request budgets, account quotas, expensive operations, and safe rejection behavior without attempting to exhaust a live service.
Updated
Understand reflected, stored, and DOM XSS assessment, browser evidence, output contexts, and why a reflected string is not proof of execution.
Updated
Assess SQL injection candidates using query review, stable controls, and safe evidence, without confusing database errors with confirmed injection.
Updated
Assess cross-origin resource sharing by connecting allowed origins, credentials, and sensitive responses to real browser behavior.
Updated
Review HTTP security headers across real application responses, prioritize practical browser protections, and avoid treating a header score as a pentest.
Updated
Plan Content Security Policy around real browser dependencies, distinguish report-only from enforcement, and retest scripts, frames, and checkout flows.
Updated
Handle suspected keys and credentials in public files without leaking them further, distinguish public identifiers, and plan safe rotation and verification.
Updated
Review cross-site request forgery around state-changing requests, token validation, cookie behavior, and safe browser confirmation.
Updated
Assess file uploads from acceptance to retrieval, including type checks, storage permissions, processing boundaries, and safe test fixtures.
Updated
Build a practical access control assessment across user roles, objects, and actions, including denied requests and valid permissions.
Updated
Assess session creation, cookie scope, privilege changes, expiry, and logout with real server requests and known test accounts.
Updated
Plan authentication assessment across sign-in, recovery, MFA, and sensitive account changes, with bounded tests and clear identity-provider limits.
Updated
Test password recovery using dedicated inboxes, token lifecycle checks, account binding, and session policy without accessing real users' accounts.
Updated
Assess SaaS workspace boundaries with separate tenants, including database records, caches, files, exports, and delayed background work.
Updated
Assess workflow rules, repeated actions, stale states, and account entitlements with safe fixtures and outcomes tied to real business impact.
Updated
Prepare a practical security testing scope with approved targets, roles, request limits, data handling, exclusions, and escalation contacts.
Updated
Evaluate security reports for scope, reproducible evidence, calibrated impact, remediation, explicit coverage limits, and retest status.
Updated
Plan security retests around the original evidence, negative and positive controls, deployment identity, adjacent routes, and clear closure outcomes.
Updated
Compare automated scanning, manual assessment, source review, and regression testing by the evidence and application context each can provide.
Updated
Map application routes, identities, data flows, integrations, and exposed assets into an owner-verified inventory with explicit assessment status.
Different approaches can provide different evidence. Compare the methods, scope, roles, and reporting you need, or discuss a focused assessment with the team.