Let's talk about your project

Insecure direct object reference

IDOR · An authorisation flaw that arises when an application, on access to a record by address or ID, does not check whether the record really belongs to the user asking for it.

  1. 01

    Why it matters

    This is a flaw that automated scanners usually miss but that is very easy to exploit: changing a single number is enough. Invoices, order details, documents and user profiles can be downloaded in bulk this way. The server has to check ownership on every request.

  2. 02

    Example

    On a portal, the invoice download address contains a sequential number. A customer who increases the number by one can download another company's invoice; after the fix, the server checks the invoice's owner on every download.

  3. 03

    Common mistake

    Thinking the problem is solved by making IDs unguessable. Random IDs only make guessing harder; the real fix is the ownership check on the server.

  4. 04
Let's begin

Let's talk about your project.

Tell us what you need; we will define the scope together.