Open cardosec

Case 1A1406 · Web AppSec · L1 Foundations

IDOR and Broken Access Control

Practise as: Explain it · Interview

Interview questionBroken access control is number one on the OWASP Top 10. What is an IDOR and how do you find and fix it?

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. IDOR: server trusts a client-supplied object ID (e.g. /api/invoices/1043) without checking the caller owns it
  2. Horizontal (other users data) vs vertical (reaching admin functions) privilege escalation
  3. Find it by replaying requests with a second account session and swapping IDs (Burp Autorize-style testing)
  4. Fix: object-level authorization checked server-side on every request, ideally centralized in a policy layer
  5. UUIDs reduce guessability but are not authorization; IDs leak via logs, referrers and other endpoints

If the interviewer pushes back

  • How would you design authorization tests so IDOR regressions are caught in CI?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.