This is great I have one question why would the ADMIN in uppercase be accessible when in lowercase it isn’t? Does that just mean the admin in lowercase file doesn’t exist but the ADMIN in uppercase page does?
I think it has to do with a filter bypass. E.g. the waf is checking for /admin but when the request reaches the backend system, it lower cases the path by default. Thus, putting /ADMIN bypasses the waf. I could be wrong. I’m still new too. Hope that helps :)
After OWASP NO 1 in 2021
This was the best talk. Just loved this one. I guess I will watch it again in a day or so. :)
Thank you for this presentation Jason.
Great content!! 😎 Thank you very much Jason 🙌
❤🙏 thanks man happy to know you
This is amazing information. Thank you for this.
on point, thankssettings page or profile page of an application has lot of idor possibility, enjoy
Waiting for the next module Very Well Explained
Thanks for sharing.. god bless you ❤
superb video and clear explanation..........
This is great I have one question why would the ADMIN in uppercase be accessible when in lowercase it isn’t? Does that just mean the admin in lowercase file doesn’t exist but the ADMIN in uppercase page does?
I think it has to do with a filter bypass. E.g. the waf is checking for /admin but when the request reaches the backend system, it lower cases the path by default. Thus, putting /ADMIN bypasses the waf. I could be wrong. I’m still new too. Hope that helps :)
@@noy5626 you're right
what is GUID?
where can I find an the videos of modules?
Does anyone know of any hacks/data breaches that have occured as a result of broken access control that i could read up on?
Thanks for posting.. your content is awesome always
Thank you
Who's here after 4 years in Aug 2022
=]
2023
@@nazneenzafar743 Good to see you
i need this ppt
Are These Tricks relevant in 2022?
yes, broken access control jumped from 5th to number 1 most common vulnerabilites.
please share sql vulunerabilitrs sql I sql Boolean timebase
Informative stuff
Plz make us understand to make a video
HEY!! PLEASE UPDATE THE CONTENT
not clearly audible.. Please change
i have been finish
up pro go on please