Case 1A1406 · Web AppSec · L1 Foundations
IDOR and Broken Access Control
Practise as: Explain it · Interview
Interview questionBroken access control is number one on the OWASP Top 10. What is an IDOR and how do you find and fix it?
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- IDOR: server trusts a client-supplied object ID (e.g. /api/invoices/1043) without checking the caller owns it
- Horizontal (other users data) vs vertical (reaching admin functions) privilege escalation
- Find it by replaying requests with a second account session and swapping IDs (Burp Autorize-style testing)
- Fix: object-level authorization checked server-side on every request, ideally centralized in a policy layer
- UUIDs reduce guessability but are not authorization; IDs leak via logs, referrers and other endpoints
If the interviewer pushes back
- How would you design authorization tests so IDOR regressions are caught in CI?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.