• IDOR series

    How does it happen

    • GET vs POST vs cookies vs headers IDOR
    • objectID or userID based
    • Secondary vs primary IDOR
    • Inter-company IDOR vs Inner company IDOR
    • normal number vs UUID vs hashed values
    • Impact
      • Destruction of data on DELETE call
      • Update or insertion of data in POST call
      • Update of data in PUT call
      • Getting data in GET call