T3chnocr4t:~#

Looking 🔭 For Something Hidden....

View on GitHub

Access Control

Lab #: User ID controlled by request parameter

Guys 👋, welcome back. Let’s go through this lab real quick. This lab has a horizontal privilege escalation vulnerability on a user account page. Let’s try to exploit the vulnerabilities.

To solve the lab, we need to obtain the API key for the user Carlos and submit it as the solution. Note: Am using caido you can follow along using burp also..

access-control


End Goals:


What Horizontal privilege escalation 🤔?

Horizontal privilege escalation occurs if a user is able to gain access to resources belonging to another user, instead of their own resources of that type.


Testing for vulnerabilities~:

1

2

3

4

5

That’s all, friends. Thank you for reading up to this point. I would like to hear your feedback on anything not clear here. Here is my Twitter account @T3chnocr4t. Feel free to DM me if you have any issues with my write-up. Thanks!

Go Back Home