Incomum · História
Insecure direct object reference
Type of access control vulnerability in digital security
Insecure direct object reference (IDOR) is a type of access control vulnerability in digital security. This can occur when a web application or application programming interface that authenticated the user to use the website, uses an identifier for direct access to an object in an internal database but does not check for access control or authentication for the file transfer.
Na Wikipédia
Texto em inglês Ainda não há artigo no seu idioma: trecho em inglês.
Insecure direct object reference (IDOR) is a type of access control vulnerability in digital security. This can occur when a web application or application programming interface that authenticated the user to use the website, uses an identifier for direct access to an object in an internal database but does not check for access control or authentication for the file transfer. For example, if the request URL sent to a web site directly uses an easily enumerated unique identifier (such as https://example.com/document/1234), this can provide an exploit for unintended access to all records. Even if the web application uses complex identifiers, a lack of access control checks can allow an attacker to access unauthorized objects if they obtain the identifier from elsewhere. A directory traversal attack is considered a special case of an IDOR. The vulnerability is of such significant concern that for many years it was listed as one of the Open Web Application Security Project's (OWASP) Top 10 vulnerabilities. Consecutive IDs can be changed into dark keys using several techniques.
Texto: Wikipédia em inglês, CC BY-SA 4.0. ·