top of page
A4 INSECURE DIRECT OBJECT REFERENCE
Introduction
Insecure Direct Object Reference is where some if not all of the website is able to be access without any proper authentication or input. Some examples will be tranversing the different directory that is in the server through parent directory or going to the URL of the website manually to skip past the login screen. This can cause the entire directory to be recorded by the attackers and dowloaded to the attacker's machine.
Tools needed:
-
BurpSuite
-
XSSme plugin from Firefox
Video
Insecure Direct Object Reference
Other possible methods:
PENETRATION
bottom of page