Bug Hunter Handbook
search
⌘Ctrlk
Bug Hunter Handbook
  • Introduction
  • Getting Started in InfoSec and Bug Bounties.
  • Presentations
  • Checklists / Guides
  • Useful Twitter Threads
  • List of Vulnerabilities
    • Recon and OSINT
    • Host Header
    • Injection
    • DNS Rebinding
    • Cross Site Scripting (XSS)
    • Cross Origin Resource Sharing (CORS)
    • Local / Remote File Inclusion (LFI / RFI)
    • Server Side Request Forgery (SSRF)
    • Remote Code Execution (RCE)
    • XML Entity Injecton (XXE)
    • Price Manipulation
    • Directory / Path Traversal
    • Cross Site Request Forgery (CSRF)
    • Password Reset
    • Login Page Issues
    • Deserialization Attacks
    • File Upload
    • Account Takeover
    • Insecure Direct Object References (IDOR)
    • Open Redirect
    • Business Logic Flaws
    • Rate Limit Bypass / 2FA / OTP Bypass
    • Ruby on Rails
    • S3 Bucket
    • Race Condition
    • CRLF
    • SSTI
    • Prototype Pollution
  • Approach
  • API Security
  • Mobile Security
  • Fuzzing / Wordlists
  • BugBounty Short Write-ups
  • Burp Suite Tips and Tricks
  • HackerOne Reports
  • Response Manipulation
  • Client Vs Server Side Vulnerabilities
  • DevSecOps
  • Containers
  • AWS
  • Azure
  • Others
  • Chaining of Bugs
  • Bug Bounty Automation
  • Mindmaps
  • Oneliner Collections
  • Red Teaming
  • Blue Teamining
  • Recon One Liners
  • Misc
  • Wordpress
  • Fuzzing / FuFF
  • OWASP ZAP
  • Bug List
  • Setting up burp collaborator
  • Admin Panel PwN
  • Credential Stuffing / Dump / HaveibeenPwned?
  • Tools Required
  • Nuclei Template
  • Other BugBounty Repos / Tips
  • Interview
  • Threat Modelling
  • AppSec
gitbookPowered by GitBook
block-quoteOn this pagechevron-down
  1. List of Vulnerabilities

Insecure Direct Object References (IDOR)

Blogs / Articles / Write-ups:

  • https://www.notion.so/IDOR-Attack-vectors-exploitation-bypasses-and-chains-0b73eb18e9b640ce8c337af83f397a6barrow-up-right

  • https://www.aon.com/cyber-solutions/aon_cyber_labs/finding-more-idors-tips-and-tricks/arrow-up-right

  • https://portswigger.net/support/using-burp-to-test-for-insecure-direct-object-referencesarrow-up-right

Looking for high impact IDOR? Always try to find the hidden parameters for this endpoints using Arjun and Parameth /settings/profile /user/profile /user/settings /account/settings /username /profile And any payment endpoint Thanks@Synackarrow-up-right #bugbountytiparrow-up-right #bugbountytipsarrow-up-right #Bugbountyarrow-up-right

Tool:

  • https://github.com/0xsapra/fuzzparamarrow-up-right

https://twitter.com/muffymas/status/1408054941445353472?s=20
  • https://www.notion.so/IDOR-Attack-vectors-exploitation-bypasses-and-chains-0b73eb18e9b640ce8c337af83f397a6barrow-up-right

  • https://16521092.medium.com/some-ways-to-find-more-idor-da16c93954e5arrow-up-right

  • https://monke.ie/oauth-idor-pii/arrow-up-right

PreviousAccount Takeoverchevron-leftNextOpen Redirectchevron-right

Last updated 4 years ago