Broken Access Control
Not every bug needs a clever payload. Broken access control is often found just by changing a 1004 to a 1005 — and it tops the OWASP list of web risks. This exercise shows how it happens, why developers keep shipping it, and the one rule that fixes it: check permission on the server, for every request.
Log in or create a free account to submit keys and track your progress.
What you will learn
- Explain what broken access control and IDOR mean
- Find an IDOR by changing an identifier in a request
- Explain the difference between authentication and authorization
- Explain the server-side ownership check that fixes it
Before you start
These exercises cover what this one builds on.
- How HTTP Works Easy
- Where Web Bugs Come From Easy
In this exercise
- Two different questions
- IDOR: change the number
- Why it keeps happening
- The fix: check ownership on the server
🔒
This is a Pro exercise
Pro unlocks every exercise, the written solutions, the video walkthroughs and badge certificates. Free exercises stay free.
See Pro plans Create a free account4 sections · 2 keys · 50 points