← All courses
PractitionerBroken access control / IDOR

Access Control in Depth

Access control is the single most reported class of bug. This path takes it seriously — from a decremented id to mass assignment to climbing roles — and finishes on a chain that turns two small gaps into a full account read.

Syllabus

  1. 1Understanding broken access controlReading10 min
  2. 2Lab: editing a profile that is not yoursLab45 min
  3. 3Lab: mass-assigning into an admin groupLab90 min
  4. 4Understanding privilege escalationReading10 min
  5. 5Lab: the role field the client should not setLab45 min