📖
NOTES
search
Ctrlk
  • Welcome!
  • Reference
    • Hackingchevron-right
      • Penetration Testing Resources Bookmarkschevron-right
      • Web/App Pentestingchevron-right
      • Port Swiggerchevron-right
        • Access controlchevron-right
          • Lab: Unprotected admin functionality
          • Unprotected admin functionality with unpredictable URL
          • User role controlled by request parameter
          • User ID controlled by request parameter, with unpredictable user IDs
          • User ID controlled by request parameter with password disclosure
        • Authenticationchevron-right
        • Server-side request forgery (SSRF)chevron-right
        • File Upload Vulnerabilitieschevron-right
        • SQL Injectionchevron-right
      • Burpchevron-right
      • ☁️Cloudchevron-right
      • Networkingchevron-right
      • Hardware Hackingchevron-right
    • HTML/CSS/JAVAchevron-right
    • DataBasechevron-right
    • PYTHON3chevron-right
    • SEOchevron-right
    • Cloudchevron-right
    • Fileschevron-right
gitbookPowered by GitBook
block-quoteOn this pagechevron-down
  1. Referencechevron-right
  2. Hackingchevron-right
  3. Port Swigger

Access control

Lab: Unprotected admin functionalitychevron-rightUnprotected admin functionality with unpredictable URLchevron-rightUser role controlled by request parameterchevron-rightUser ID controlled by request parameter, with unpredictable user IDschevron-rightUser ID controlled by request parameter with password disclosurechevron-right
PreviousPort Swiggerchevron-leftNextLab: Unprotected admin functionalitychevron-right

Last updated 2 years ago