Uncommon · History
Insecure direct object reference
Type of access control vulnerability in digital security
Insecure direct object reference (IDOR) is a type of access control vulnerability in digital security. This can occur when a web application or application programming interface that authenticated the user to use the website, uses an identifier for direct access to an object in an internal database but does not check for access control or authentication for the file transfer.
From Wikipedia
Insecure direct object reference (IDOR) is a type of access control vulnerability in digital security. This can occur when a web application or application programming interface that authenticated the user to use the website, uses an identifier for direct access to an object in an internal database but does not check for access control or authentication for the file transfer. For example, if the request URL sent to a web site directly uses an easily enumerated unique identifier (such as https://example.com/document/1234), this can provide an exploit for unintended access to all records. Even if the web application uses complex identifiers, a lack of access control checks can allow an attacker to access unauthorized objects if they obtain the identifier from elsewhere. A directory traversal attack is considered a special case of an IDOR. The vulnerability is of such significant concern that for many years it was listed as one of the Open Web Application Security Project's (OWASP) Top 10 vulnerabilities. Consecutive IDs can be changed into dark keys using several techniques.
Text: Wikipédia, CC BY-SA 4.0. ·
Related cards
-
★★★
Access control
Selective restriction of access to a place or other resource, allowing only authorized users
-
★
Dirty COW
Computer security vulnerability
-
N★
NIPRNet
One of the United States Department of Defense's three main networks
-
★★★★
General Directorate for Internal Security
France interior intelligence agency
-
★★
Security through obscurity
Secrecy of the design or implementation as the main method of providing security
-
★
Tokenization (data security)
Concept in data security