How to search for IDORs!

Поділитися
Вставка
  • Опубліковано 31 тра 2024
  • 👩‍🎓👨‍🎓 Learn how you search for IDOR (Insecure Direct Object Reference) vulnerabilities. In this video, we are going to see an example of what to look out for.
    Overview:
    00:00 Intro
    00:15 Lab overview
    01:06 Exploring the vulnerable functionality
    02:08 Direct Object Reference
    02:39 Exploiting the app
    03:24 Solving the lab
    03:50 Conclusion
    For more information, check out blog.intigriti.com/hackademy/...
    🔗 Portswigger IDOR Challenge: portswigger.net/web-security/...
    ---
    🧑‍💻 Sign up and start hacking right now - go.intigriti.com/register
    👾 Join our Discord - go.intigriti.com/discord
    🎙️ This show is hosted by / pascalsec (@Hacksplained ) & / intigriti
    👕 Do you want some Intigriti Swag? Check out swag.intigriti.com/

КОМЕНТАРІ • 33

  • @user-ni7rd7st8z
    @user-ni7rd7st8z Рік тому

    谢谢你,讲解的非常有趣,简洁易懂,不失风趣

    • @intigriti
      @intigriti  Рік тому

      Whoops, we only know English!

  • @danail.
    @danail. 2 роки тому

    Nice video, keep it up 👍

    • @intigriti
      @intigriti  2 роки тому +1

      Thanks for the visit 🔥 Share the love!

  • @nemzyxt
    @nemzyxt Рік тому

    Thanks a lot for this :)

  • @JuanBotes
    @JuanBotes 2 роки тому +1

    thanks for the content \o/

  • @Alexander007A
    @Alexander007A 11 місяців тому

    hello. i learn the iodor concept but I didn't know what to do next and where I do actually.. i solved the lab
    i need your help thank you

    • @intigriti
      @intigriti  11 місяців тому

      Hi there! I'm not too sure what you're asking for help with? Did you already solve the lab or you're stuck at part of it? 😕

    • @Alexander007A
      @Alexander007A 11 місяців тому

      @@intigriti yes I did... Solved it and I understand the concept but I didn't know how I do in real website?? How I'll find bug in real one .. like how to choose website in hacker one or other

    • @intigriti
      @intigriti  11 місяців тому +1

      If you want to see how to find IDORs real websites, best to go and look at reports demonstrating how other hackers have found IDORs 😉 Check this out: medium.com/@nynan/what-i-learnt-from-reading-220-idor-bug-reports-6efbea44db7

  • @robroy289
    @robroy289 Рік тому +1

    Maybe I missed it...how did you get the user name for the password?

    • @intigriti
      @intigriti  Рік тому +1

      It's given in the lab's description!

    • @IAmScarab
      @IAmScarab Рік тому

      Had me stuck for a while as well until I figured it out, just gotta read the docs.

  • @fahadfaisal2383
    @fahadfaisal2383 2 роки тому +1

    ">

    • @intigriti
      @intigriti  2 роки тому +2

      Well, that's a different vulnerability class 😅

    • @fahadfaisal2383
      @fahadfaisal2383 2 роки тому

      @@intigriti 😂 I like xss so much

  • @umarahmad9737
    @umarahmad9737 2 роки тому

    How to find IDOR Vulnerability in Long Number Ids & Random Unique Ids

    • @intigriti
      @intigriti  2 роки тому +3

      Those are generally secure to be used by a company. The only thing that could happen is that those non-enumerable IDs are leaked somewhere else on the website. Then, you can try to use them and find an IDOR vuln.

    • @umarahmad9737
      @umarahmad9737 2 роки тому

      @@intigriti OK , Thanks ❤

  • @gabrielgerzvolf
    @gabrielgerzvolf Рік тому +1

    How did you figure out that the username is Carlos?

    • @intigriti
      @intigriti  Рік тому

      The challenge description: "Solve the lab by finding the password for the user carlos, and logging into their account."

    • @gabrielgerzvolf
      @gabrielgerzvolf Рік тому +1

      @@intigriti I missed the part of the challenge question. Thank you for clearing that out. :)

  • @user-ni7rd7st8z
    @user-ni7rd7st8z Рік тому

    希望以后能看到更多关于你的视频

    • @intigriti
      @intigriti  Рік тому

      Whoops, we only know English!

  • @alan.m.rebeira
    @alan.m.rebeira 2 роки тому

    👍😎

  • @derelictmanchester8745
    @derelictmanchester8745 Рік тому

    What if you get the prompt.."username does not match.."

    • @intigriti
      @intigriti  Рік тому

      Then you have not found the right username password combination. The video should give you a pretty good idea though how you can find it!

    • @derelictmanchester8745
      @derelictmanchester8745 4 місяці тому

      In this example, hypothetical...as you used 'carlos' and the pword from 1.txt....yeah...but no username indicated.

  • @MichaelCooter
    @MichaelCooter 2 роки тому +1

    First!!