Skip to content
#

broken-access-control

Here are 63 public repositories matching this topic...

🧿 AutorizePro是一款强大越权检测 Burp 插件,通过增加 AI 辅助分析 && 进一步优化检测逻辑,大幅降低误报率,提升越权漏洞检出效率。 [ AutorizePro is a authorization enforcement detection extension for burp suite. By adding Ai-assisted analysis, it significantly reduces the false positive rate and improves the efficiency of vulnerability detection.

  • Updated Jan 18, 2026
  • Python

🛡️ Multi-tenant isolation auditor — proves whether tenant A can reach tenant B's data. Seeds two tenants, attacks one as the other, and reports confirmed BOLA/IDOR leaks with canary-backed evidence. CI merge gate, near-zero false positives. One command: docker compose up -d

  • Updated Jul 28, 2026
  • Python
overstep

Authorization testing for REST APIs and MCP servers. Declare who may do what as a matrix, and overstep turns it into positive and negative tests that catch BOLA, BFLA, BOPLA and privilege escalation — with drift baselines, confidence grading and CWE/OWASP-tagged SARIF for CI.

  • Updated Aug 20, 2026
  • Python

Add this topic to your repo

To associate your repository with the broken-access-control topic, visit your repo's landing page and select "manage topics."

Learn more