top of page

A7 MISSING FUNCTION LEVEL ACCESS CONTROL

Introduction

Missing function level access control is where users can login and change their control to access as an administrator. This can cause a lack of accountability to the account as the admin can login as a user and a user can log in as an admin. This will cause massive information to be leaked out or can cause a denial of service to the users.

Tools needed:
  • BurpSuite

Video

Admin access as a user

Other possible methods:

Some tips of solving the vulnerability is to:

 

  • Check for priviledges against the server before allowing access

  • Have a seperate encryption key for the admin access and reject any other encryption. 

PENETRATION

Testing

© 2015 - 2016 by Pen tester Ezekiel. Proudly created with Wix.com 

bottom of page