Broken Access Control

🔒 Pro Medium Course Online Avg. time 30 min Solved by 0 2 keys · 50 pts Access & Authentication

Not every bug needs a clever payload. Broken access control is often found just by changing a 1004 to a 1005 — and it tops the OWASP list of web risks. This exercise shows how it happens, why developers keep shipping it, and the one rule that fixes it: check permission on the server, for every request.

Log in or create a free account to submit keys and track your progress.

What you will learn

  • Explain what broken access control and IDOR mean
  • Find an IDOR by changing an identifier in a request
  • Explain the difference between authentication and authorization
  • Explain the server-side ownership check that fixes it

Before you start

These exercises cover what this one builds on.

In this exercise

  1. Two different questions
  2. IDOR: change the number
  3. Why it keeps happening
  4. The fix: check ownership on the server
🔒

This is a Pro exercise

Pro unlocks every exercise, the written solutions, the video walkthroughs and badge certificates. Free exercises stay free.

See Pro plans Create a free account

4 sections · 2 keys · 50 points