Burp plugin to test for authorization flaws Usage: Right click action to "Send request(s) to Authz" Create a modified cookie - presumably for a different user Click 'Run' Notice differences in responses