IDORs: What are they and how do you look for them

แชร์
ฝัง
  • เผยแพร่เมื่อ 27 พ.ย. 2020
  • Insecure direct object reference: IDORs
    / idors-what-are-they-an...
    IDOR playlist: • Bug Bounty Bits: find ...
    Become a member of this channel to unlock special perks: / @thexssrat
    You can now Buy me a block of cheese:
    www.buymeacoffee.com/thexssrat
    Patreon:
    / thexssrat
    Instagram:
    thexssrat
    Follow me on twitter to be notified when i release a new video:
    / thexssrat
    Come join our discord :D i hang out there often!
    / discord
  • แนวปฏิบัติและการใช้ชีวิต

ความคิดเห็น • 13

  • @lxa1121
    @lxa1121 3 ปีที่แล้ว +6

    If anyone watches this, make sure you watch it until the end. He makes a ... i mean, you make very good points bud!

    • @TheXSSrat
      @TheXSSrat  3 ปีที่แล้ว +2

      Thanks friend 😍

    • @BSt3ph
      @BSt3ph 3 ปีที่แล้ว

      Yea! sure 👍

  • @oldGoatMilk
    @oldGoatMilk 3 ปีที่แล้ว +3

    FLOOR GANG!! Thanks for the info, it's always appreciated!
    Something I've tried
    - Add .json to the endpoint, if it is built in Ruby!
    ```html
    /user_data/2341 --> 401 Unauthorized
    /user_data/2341.json --> 200 OK
    ```

  • @6060fishy
    @6060fishy 3 ปีที่แล้ว +1

    That was awesome thanks! I have been looking forward to watching this since the notification popped! I am adding IDORs to my metholodgy now.... no doubt I’ll be asking loads of questions in Discord!

    • @TheXSSrat
      @TheXSSrat  3 ปีที่แล้ว +1

      Fire away :D uncle ern always has a spot on his lap

  • @achintyavatsraj288
    @achintyavatsraj288 3 ปีที่แล้ว +1

    Man oh man as always learned so much 🔥

  • @gurpwindoo1928
    @gurpwindoo1928 ปีที่แล้ว +1

    I know this is an old video, but wouldn't fuzzing count as a way to find some IDORs?

    • @TheXSSrat
      @TheXSSrat  ปีที่แล้ว

      I don’t know, it’s said to be but I don’t buy the idea. Id you can access one persona’s data you can usually access every personas data. Maybe if they use a non sequential ID otherwise the best use case I see is with parameter discovery 😃

  • @saranshrayguru2399
    @saranshrayguru2399 3 ปีที่แล้ว +1

    Hey, thank you for your advice, I have a req can you make a video on RCE , I mean I heard from insiderphd it's very hard, but hey there must me a starting point, that where to start, Want to hear your point of view, or else it will be great if you some of your thoughts in twitter

    • @TheXSSrat
      @TheXSSrat  3 ปีที่แล้ว

      Thank you bro 😍 would love that topic! I added it to my todo list! Thanks so much friend

  • @antoniosalinas8178
    @antoniosalinas8178 3 ปีที่แล้ว

    never found an IDOR and people say its easy to find them XD
    its easier to get information disclosure.

    • @TheXSSrat
      @TheXSSrat  3 ปีที่แล้ว +1

      The problem is that you have to look for IDORs on functionality that’s not easy to find :D