Zap for IDOR
Occurs when applications expose internal object identifiers (like user IDs or filenames) without proper authorization checks, allowing attackers to access or modify other users’ data.
I have discovered this tool with this level: IDOR - Santa’s Little IDOR

You can access to storage section and see that they store your access through a simple id:

Now you can update it by hand and refresh to see the panel of another one.
Now let’s scrap it with zap:
As you can see we found the request, let’s automate:

We got some pretty result let’s find out.
Just need to take a look for now !