OWASP Security Shepherd Project - Insecure Direct Object Reference 1 (Insecure Direct Object Reference Challenge)

Challenge


Solution

    In this challenge, we want to find a private message for a user who isn't listed by default.
Let's click Show this Profile button and check the HTTP requests.
















    So... Based on the information we got, the userId are 1,3,5,7,9. As a result, it is not difficult to guess to next person is 11. Let's give it a try.


    WOW! Fairly easy!

留言

The Hottest Articles

OWASP Security Shepherd Project - My Practice & Solutions

OSCP回顧 & 準備建議

OWASP Security Shepherd Project - SQL Injection 3 (Injection Challenge)