Slide 6 of 28
Part 1 · What Is It?Slide 6
Slide 6 · The Attackers
You don't need to be a hacker.
That's the scariest part about BOLA.
What it actually takes

To exploit BOLA you need exactly three things:

1. A valid account. Sign up for free. Anyone can do this.

2. The ability to look at a URL or a network request. Right-click → Inspect → Network tab. Every browser has this built in.

3. The ability to change a number. That's it. Backspace. Type a different number. Hit enter.

What people imagine
Years of hacking experience
Custom exploit tools
Breaking encryption
Sophisticated malware
What BOLA actually needs
A browser
A free account on the app
Curiosity
Change one number
Who actually does this

Bug bounty hunters. Bored users. Journalists investigating data practices. Competitors. And yes — criminals who realize no skill is required. The low bar is what makes BOLA the #1 API risk. The data is practically in the open.

← Back Understood → Is there another one like this? →