Insecure Direct Object References
Post
Cancel

Insecure Direct Object References

Insecure Direct Object References

Insecure Direct Object References occur when an application provides direct access to objects based on user-supplied input. As a result of this vulnerability attackers can bypass authorization and access resources in the system directly, for example database records or files. - OWASP

Summary

Tools

  • Burp Suite plugin Authz
  • Burp Suite plugin AuthMatrix
  • Burp Suite plugin Authorize

Exploit

https://lh5.googleusercontent.com/VmLyyGH7dGxUOl60h97Lr57F7dcnDD8DmUMCZTD28BKivVI51BLPIqL0RmcxMPsmgXgvAqY8WcQ-Jyv5FhRiCBueX9Wj0HSCBhE-_SvrDdA6_wvDmtMSizlRsHNvTJHuy36LG47lstLpTqLK

The value of a parameter is used directly to retrieve a database record.

1
http://foo.bar/somepage?invoice=12345

The value of a parameter is used directly to perform an operation in the system

1
http://foo.bar/changepassword?user=someuser

The value of a parameter is used directly to retrieve a file system resource

1
http://foo.bar/showImage?img=img00011

The value of a parameter is used directly to access application functionality

1
http://foo.bar/accessPage?menuitem=12

Examples

References

This post is licensed under CC BY 4.0 by the author.