Download as docx, pdf, or txt
Download as docx, pdf, or txt
You are on page 1of 8

Definitions : 1) A direct object reference occurs when a developer exposes a reference to an internal implementation object, such as a file, directory,

or database key. Without an access control check or other protection, attackers can manipulate these references to access unauthorized data.

2) The Insecure Direct Object References represent the flaws in system design where access to sensitive data/assets is not fully protected and data objects are exposed by application with assumption that user will always follow the application rules 3) Insecure Direct Object Reference is when a web application exposes an internal implementation object to the user

How to do :

http://vunerableSite.com/cms/accountInfo?LoggedIn=True&userID=45674 Your Account http://vunerableSite.com/cms/accountInfo?LoggedIn=True&userID=45675 Not Your Account

You might also like