Slide 16 of 28
Part 3 · Attack ScenariosSlide 16
Slide 16 · Scenarios 7–9
Documents. Smart homes. Salaries.
BOLA reaches into work, home, and HR.
SCENARIO 07 · Document Management
A private contract is one ID change away.

A document platform stores files at /api/documents/DOC-2281. A user with a legitimate account changes the document ID and retrieves a contract, NDA, or financial report that was never shared with them. The document was marked private — but the API didn't enforce it.

Why it matters: Confidential business documents — M&A agreements, employee contracts, legal filings — have enormous value to competitors and bad actors.
SCENARIO 08 · Smart Home / IoT
Someone else controls your front door lock.

A smart home platform manages devices at /api/devices/D-5591/control. A user changes the device ID and sends a command to someone else's smart lock, thermostat, or security camera. The API verified the user was logged in — not that the device was theirs.

Why it matters: Physical access, home temperature, surveillance — IoT BOLA crosses from digital harm into the physical world. This isn't data on a screen. It's someone's front door.
SCENARIO 09 · HR System
Any employee can read any other employee's salary.

An HR platform exposes payroll data at /api/employees/EMP-0441/compensation. An employee changes the ID and reads a colleague's — or their manager's — full compensation breakdown: salary, bonus, equity, benefits.

Why it matters: Salary data is sensitive and legally protected in many places. Exposure creates workplace conflict, discrimination claims, and competitive intelligence for rivals.
← Back What do all of these have in common? →