vulns.co
/
GKData.io MCP

Back to Playbooks

IDOR & Broken Access Control

Systematically test whether one user can reach another user's objects or actions.

Tags: idor, bac, authz, owasp-a01

Level: intermediate

Method

  1. Map object references

    Proxy the app and catalog every request carrying an ID, UUID, filename, or account reference.

    Tools: Burp Suite, Caido

  2. Set up two accounts

    Create User A and User B. Capture A's requests, then replay them as B (swap session, keep A's object IDs).

    Tools: Burp Suite

  3. Swap and observe

    Change IDs incrementally and via B's session. A 200 with A's data = IDOR. Test all verbs (GET/POST/PUT/DELETE).

  4. Automate the sweep

    For numeric IDs, script the range and diff response sizes/status to spot leaks.

    ffuf -u https://target.com/api/orders/FUZZ -w <(seq 1000 2000) -H 'Cookie: session=USER_B' -mc 200

    Tools: ffuf

Field notes

  • Don't ignore UUIDs - they leak in other responses more often than you'd think.
  • Test tenant boundaries and role escalation, not just user-to-user.
  • Blind writes matter too: a successful DELETE/PUT on another's object is high impact.

References