← Web Security Foundations
ReadingLesson 2 of 5 · 10 min
Understanding broken access control
What it is
Access control is the rule that a request may only touch what its owner is allowed to touch. When the id of a record travels in the URL, the body or a header, and the server trusts it without checking who is asking, one account can read or change another's data by editing that id.
How you approach it
- Watch the requests the page makes. Which one carries a number or an id that looks like it identifies your record specifically?
- Change that id to a neighbouring value. Does the server check that the record belongs to you, or does it just return it?
- The flag sits on a record a few ids away from your own. Walk the ids until the response body changes shape.
How it gets fixed
The endpoint returned any record by id with no ownership check — a textbook IDOR. Intercepting the request and decrementing the id walked straight into another tenant's object, where the flag was stored. The fix is an authorization check on every object read, keyed to the session rather than to the id in the request.
Practise it
Every lab in the Broken access control / IDOR category drills exactly this. Start at Apprentice and work up.