Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Bugcrowd University - Broken Access Control Testing

Bugcrowd via YouTube

Overview

Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
This lesson teaches techniques for finding broken access control in web applications, with examples including IDOR variants, forceful browsing, and parameter manipulation. It also covers creating a function matrix for MFLAC and using Burp Intruder.

Syllabus

Intro
Module Trainer
Module Outline
Module Reading
Introduction to Access Control bugs
Simple numeric IDOR
Bugcrowd VRT Rating
GUID based IDOR (cont.)
Hash based IDOR
Request methods
Local File Inclusion and Path Traversal
Static pages & "forceful browsing"
Static files
Direct function calling
Parameter Manipulation
Logic Flaws
Auxiliary Tips
Likely parameters/keyword to check for IDOR
COTS, OSS, and paywalled applications
Create a function matrix for MFLAC
Burp Intruder
References

Taught by

Bugcrowd

Reviews

Start your review of Bugcrowd University - Broken Access Control Testing

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.