kyou
Ctrlk
  • WHOAMI
    • Robemar Aviles
  • Tryhackme
    • View
  • Hack the box
    • View
  • Academy HTB
    • View
  • Over The Wire
    • View
  • Under The Wire
    • View
  • PicoCTF
    • View
  • Portswigger
    • View
  • Hacker101
    • View
  • Python
    • View
  • SQL
    • View
  • Notes
    • View
  • Commands
    • View
  • Google Chrome Password
  • Comptia Security+ 701
  • CCNA
  • Malware Analysis Lab
  • TCM
    • Linux 100: Fundamentals
    • Programming 100: Fundamentals
    • Practical Bug Bounty
    • Practical Web Hacking
      • Authentication
      • Access Control
        • Lab: User ID controlled by request parameter
        • Lab: Unprotected admin functionality
        • Lab: Insecure direct object references
        • Lab: Multi-step process with no access control on one step
        • Lab: Referer-based access control
      • SSRF
      • LFI/RFI
      • XXE
      • JWTs
      • find
      • ffuf
    • Web pen
Powered by GitBook
On this page
  1. TCM
  2. Practical Web Hacking

Access Control

Lab: User ID controlled by request parameterLab: Unprotected admin functionalityLab: Insecure direct object referencesLab: Multi-step process with no access control on one stepLab: Referer-based access control
PreviousLab: 2FA simple bypassNextLab: User ID controlled by request parameter