Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

HackingHub

Broken Access Control (BAC) Masterclass

via HackingHub

Overview

Google, IBM & Meta Certificates – 40% Off
One plan covers every Professional Certificate on Coursera.
Unlock All Certificates

Learn how modern APIs fail, how attackers discover hidden functionality, and how small authorization mistakes turn into full compromise.

Broken access control has been the #1 web application vulnerability for years. It shows up in every SaaS platform, healthcare app, fintech API, and multi-tenant tool you will ever test. Yet most security courses barely scratch the surface. This course teaches you how to find and exploit it the way real attackers do.

What You Get

Two full lab environments built from scratch for this course.

MedConnect

A multi-tenant healthcare platform with patients, nurses, doctors, multiple organizations, JWT authentication, legacy API versions, hidden admin functionality, and Swagger documentation. Every vulnerability is woven into the application naturally. You discover information in one area that helps you attack another. Hidden endpoints lead to legacy APIs. Legacy APIs lead to impersonation. Impersonation leads to cross-org compromise.

TaskForge

A project management application used as your final challenge. Two organizations, four users, 5 hidden flags. No hand-holding. Find and exploit as many access control flaws as you can using everything you learned in the course.

What You Will Learn

The course covers the full spectrum of broken access control.

  • IDOR across GET, POST, PUT, PATCH, DELETE
  • Privilege escalation (patient to admin)
  • JWT decoding, forgery, and abuse
  • API versioning and legacy endpoints
  • Mass assignment and foreign key manipulation
  • Cross-tenant data access
  • HTTP method switching bypasses
  • Hidden admin functionality
  • Filter and parameter manipulation
  • Predictable token exploitation
  • Chaining findings into full compromise
  • Frontend JavaScript analysis

Using AI to Hack Smarter

Three dedicated modules on using AI for security testing. Practical workflows you can apply immediately on real targets.

  • API Specification Analysis
    Feed API specs to AI to quickly identify interesting endpoints and authorization gaps.
  • Payload Generation and Automation
    Use AI to generate attack payloads and write proof-of-concept scripts in Python.
  • JavaScript Analysis
    Analyze frontend JavaScript with AI to uncover hidden endpoints, hardcoded roles, and internal API references.

Who This Is For

  • Bug bounty hunters targeting APIs
  • Pentesters who want stronger API testing methodology
  • AppSec engineers reviewing SaaS applications
  • Developers who want to understand how authorization fails
  • Anyone ready to move beyond checklists and think like an attacker

What You Walk Away With

By the end of this course you will be able to confidently test modern APIs, discover hidden functionality, exploit broken authorization across multiple vulnerability classes, assess multi-tenant applications for tenant isolation failures, chain findings together into high-impact attack paths, and use AI to accelerate your recon and exploitation workflow.

Get Instant Access

Modern applications are full of hidden trust assumptions.

This course teaches you how to find them.

Syllabus

What You Will Learn

The course covers the full spectrum of broken access control.

  • IDOR across GET, POST, PUT, PATCH, DELETE
  • Privilege escalation (patient to admin)
  • JWT decoding, forgery, and abuse
  • API versioning and legacy endpoints
  • Mass assignment and foreign key manipulation
  • Cross-tenant data access
  • HTTP method switching bypasses
  • Hidden admin functionality
  • Filter and parameter manipulation
  • Predictable token exploitation
  • Chaining findings into full compromise
  • Frontend JavaScript analysis

Reviews

Start your review of Broken Access Control (BAC) Masterclass

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.