Resources
- https://portswigger.net/web-security/access-control
- https://blog.detectify.com/2016/07/13/owasp-top-10-missing-function-level-access-control-7/
- https://owasp.org/www-pdf-archive/OWASP_Top_10-2017_%28en%29.pdf.pdf
- https://owasp.org/www-community/Broken_Access_Control
- https://github.com/globocom/secDevLabs/tree/master/owasp-top10-2017-apps/a5/ecommerce-api
- https://github.com/globocom/secDevLabs/tree/master/owasp-top10-2017-apps/a5/tictactoe
- https://owasp.org/Top10/A01_2021-Broken_Access_Control/
- https://avatao.com/blog-broken-access-control/
- https://www.prplbx.com/resources/blog/broken-access-control/
- https://github-wiki-see.page/m/Muamaidbengt/juice-shop/wiki/Lab-04-Broken-Access-Control
- https://www.youtube.com/watch?v=94-tlOCApOc&t=5s
- https://book.hacktricks.xyz/pentesting-web/idor
- https://medium.com/@aysebilgegunduz/everything-you-need-to-know-about-idor-insecure-direct-object-references-375f83e03a87
- https://portswigger.net/web-security/access-control/idor
- https://thehackerish.com/idor-tutorial-hands-on-owasp-top-10-training/
- https://hackerone.com/reports/1085782 [An interesting report on an IDOR disclosing critical PII]
- https://medium.com/@gulprit_singh/account-takeover-through-idor-2e4a7882c334
- https://payatu.com/blog/prateek.thakare/broken-access-control
- https://galnagli.com/Samsung_Exposure/
- https://infosecwriteups.com/dank-writeup-on-broken-access-control-on-an-indian-startup-d29132a1ecd