Insecure Direct Object Reference (IDOR)
Insecure Direct Object Reference (IDOR)
Locations:
1: URL
2: JS Files
3: Content loaded via an AJAX request
IDs
1: Encoded (Base64)
2: Hashed (MD5)
3: Unpredictable (Create 2 accounts and swap ID numbers between them)
IDOR
Steps
Examples:
Last updated