daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

index.md (7802B)


      1 ---
      2 title: "Insecure Direct Object References"
      3 topic: "Insecure Direct Object References"
      4 topicSlug: "insecure-direct-object-references"
      5 sourcePath: "Insecure Direct Object References/README.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/Insecure%20Direct%20Object%20References/README.md"
      7 sha: "3ac27901c711"
      8 isReadme: true
      9 ---
     10 
     11 # Insecure Direct Object References
     12 
     13 > Insecure Direct Object References (IDOR) is a security vulnerability that occurs when an application allows users to directly access or modify objects (such as files, database records, or URLs) based on user-supplied input, without sufficient access controls. This means that if a user changes a parameter value (like an ID) in a URL or API request, they might be able to access or manipulate data that they aren’t authorized to see or modify.
     14 
     15 ## Summary
     16 
     17 * [Tools](#tools)
     18 * [Methodology](#methodology)
     19     * [Numeric Value Parameter](#numeric-value-parameter)
     20     * [Common Identifiers Parameter](#common-identifiers-parameter)
     21     * [Weak Pseudo Random Number Generator](#weak-pseudo-random-number-generator)
     22     * [Hashed Parameter](#hashed-parameter)
     23     * [Wildcard Parameter](#wildcard-parameter)
     24     * [IDOR Tips](#idor-tips)
     25 * [Labs](#labs)
     26 * [References](#references)
     27 
     28 ## Tools
     29 
     30 * [PortSwigger/BApp Store > Authz](https://portswigger.net/bappstore/4316cc18ac5f434884b2089831c7d19e)
     31 * [PortSwigger/BApp Store > AuthMatrix](https://portswigger.net/bappstore/30d8ee9f40c041b0bfec67441aad158e)
     32 * [PortSwigger/BApp Store > Autorize](https://portswigger.net/bappstore/f9bbac8c4acf4aefa4d7dc92a991af2f)
     33 
     34 ## Methodology
     35 
     36 IDOR stands for Insecure Direct Object Reference. It's a type of security vulnerability that arises when an application provides direct access to objects based on user-supplied input. As a result, attackers can bypass authorization and access resources in the system directly, potentially leading to unauthorized information disclosure, modification, or deletion.
     37 
     38 **Example of IDOR**:
     39 
     40 Imagine a web application that allows users to view their profile by clicking a link `https://example.com/profile?user_id=123`:
     41 
     42 ```php
     43 <?php
     44     $user_id = $_GET['user_id'];
     45     $user_info = get_user_info($user_id);
     46     ...
     47 ```
     48 
     49 Here, `user_id=123` is a direct reference to a specific user's profile. If the application doesn't properly check that the logged-in user has the right to view the profile associated with `user_id=123`, an attacker could simply change the `user_id` parameter to view other users' profiles:
     50 
     51 ```ps1
     52 https://example.com/profile?user_id=124
     53 ```
     54 
     55 ![https://lh5.googleusercontent.com/VmLyyGH7dGxUOl60h97Lr57F7dcnDD8DmUMCZTD28BKivVI51BLPIqL0RmcxMPsmgXgvAqY8WcQ-Jyv5FhRiCBueX9Wj0HSCBhE-_SvrDdA6_wvDmtMSizlRsHNvTJHuy36LG47lstLpTqLK](https://raw.githubusercontent.com/swisskyrepo/PayloadsAllTheThings/3ac27901c711/Insecure%20Direct%20Object%20References/Images/idor.png)
     56 
     57 ### Numeric Value Parameter
     58 
     59 Increment and decrement these values to access sensitive information.
     60 
     61 * Decimal value: `287789`, `287790`, `287791`, ...
     62 * Hexadecimal: `0x4642d`, `0x4642e`, `0x4642f`, ...
     63 * Unix epoch timestamp: `1695574808`, `1695575098`, ...
     64 
     65 **Examples**:
     66 
     67 * [HackerOne - IDOR to view User Order Information - meals](https://hackerone.com/reports/287789)
     68 * [HackerOne - Delete messages via IDOR - naaash](https://hackerone.com/reports/697412)
     69 
     70 ### Common Identifiers Parameter
     71 
     72 Some identifiers can be guessed like names and emails, they might grant you access to customer data.
     73 
     74 * Name: `john`, `doe`, `john.doe`, ...
     75 * Email: `john.doe@mail.com`
     76 * Base64 encoded value: `am9obi5kb2VAbWFpbC5jb20=`
     77 
     78 **Examples**:
     79 
     80 * [HackerOne - Insecure Direct Object Reference (IDOR) - Delete Campaigns - datph4m](https://hackerone.com/reports/1969141)
     81 
     82 ### Weak Pseudo Random Number Generator
     83 
     84 * UUID/GUID v1 can be predicted if you know the time they were created: `95f6e264-bb00-11ec-8833-00155d01ef00`
     85 * MongoDB Object Ids are generated in a predictable manner: `5ae9b90a2c144b9def01ec37`
     86     * a 4-byte value representing the seconds since the Unix epoch
     87     * a 3-byte machine identifier
     88     * a 2-byte process id
     89     * a 3-byte counter, starting with a random value
     90 
     91 **Examples**:
     92 
     93 * [HackerOne - IDOR allowing to read another user's token on the Social Media Ads service - a_d_a_m](https://hackerone.com/reports/1464168)
     94 * [IDOR through MongoDB Object IDs Prediction](https://techkranti.com/idor-through-mongodb-object-ids-prediction/)
     95 
     96 ### Hashed Parameter
     97 
     98 Sometimes we see websites using hashed values to generate a random user id or token, like `sha1(username)`, `md5(email)`, ...
     99 
    100 * MD5: `098f6bcd4621d373cade4e832627b4f6`
    101 * SHA1: `a94a8fe5ccb19ba61c4c0873d391e987982fbbd3`
    102 * SHA2: `9f86d081884c7d659a2feaa0c55ad015a3bf4f1b2b0b822cd15d6c15b0f00a08`
    103 
    104 **Examples**:
    105 
    106 * [IDOR with Predictable HMAC Generation - DiceCTF 2022 - CryptoCat](https://youtu.be/Og5_5tEg6M0)
    107 
    108 ### Wildcard Parameter
    109 
    110 Send a wildcard (`*`, `%`, `.`, `_`) instead of an ID, some backend might respond with the data of all the users.
    111 
    112 * `GET /api/users/* HTTP/1.1`
    113 * `GET /api/users/% HTTP/1.1`
    114 * `GET /api/users/_ HTTP/1.1`
    115 * `GET /api/users/. HTTP/1.1`
    116 
    117 ### IDOR Tips
    118 
    119 * Change the HTTP request: `POST → PUT`
    120 * Change the content type: `XML → JSON`
    121 * Transform numerical values to arrays: `{"id":19} → {"id":[19]}`
    122 * Use Parameter Pollution: `user_id=hacker_id&user_id=victim_id`
    123 
    124 ## Labs
    125 
    126 * [PortSwigger - Insecure Direct Object References](https://portswigger.net/web-security/access-control/lab-insecure-direct-object-references)
    127 
    128 ## References
    129 
    130 * [From Christmas present in the blockchain to massive bug bounty - Jesse Lakerveld - March 21, 2018](http://web.archive.org/web/20180401130129/https://www.vicompany.nl/magazine/from-christmas-present-in-the-blockchain-to-massive-bug-bounty)
    131 * [How-To: Find IDOR (Insecure Direct Object Reference) Vulnerabilities for large bounty rewards - Sam Houton - November 9, 2017](https://web.archive.org/web/20260221194813/https://www.bugcrowd.com/blog/how-to-find-idor-insecure-direct-object-reference-vulnerabilities-for-large-bounty-rewards/)
    132 * [Hunting Insecure Direct Object Reference Vulnerabilities for Fun and Profit (PART-1) - Mohammed Abdul Raheem - February 2, 2018](https://web.archive.org/web/20190509043727/https://codeburst.io/hunting-insecure-direct-object-reference-vulnerabilities-for-fun-and-profit-part-1-f338c6a52782)
    133 * [IDOR - how to predict an identifier? Bug bounty case study - Bug Bounty Reports Explained - September 21, 2023](https://web.archive.org/web/20231027235449/https://youtu.be/wx5TwS0Dres)
    134 * [Insecure Direct Object Reference Prevention Cheat Sheet - OWASP - July 31, 2023](https://web.archive.org/web/20140316052400/https://www.owasp.org/index.php/Insecure_Direct_Object_Reference_Prevention_Cheat_Sheet)
    135 * [Insecure direct object references (IDOR) - PortSwigger - December 25, 2019](https://web.archive.org/web/20260301072233/https://portswigger.net/web-security/access-control/idor)
    136 * [Testing for IDORs - PortSwigger - October 29, 2024](https://web.archive.org/web/20230604162333/https://portswigger.net/burp/documentation/desktop/testing-workflow/access-controls/testing-for-idors)
    137 * [Testing for Insecure Direct Object References (OTG-AUTHZ-004) - OWASP - August 8, 2014](https://web.archive.org/web/20170712205114/https://www.owasp.org/index.php/Testing_for_Insecure_Direct_Object_References_(OTG-AUTHZ-004))
    138 * [The Rise of IDOR - HackerOne - April 2, 2021](https://web.archive.org/web/20211004153030/https://www.hackerone.com/company-news/rise-idor)
    139 * [Web to App Phone Notification IDOR to view Everyone's Airbnb Messages - Brett Buerhaus - March 31, 2017](https://web.archive.org/web/20170408053950/http://buer.haus:80/2017/03/31/airbnb-web-to-app-phone-notification-idor-to-view-everyones-airbnb-messages)