> For the complete documentation index, see [llms.txt](https://book.redsquad.xyz/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://book.redsquad.xyz/web-hacking/web-vulnerabilities/insecure-direct-object-reference-idor.md).

# IDOR

<details>

<summary>What is IDOR ?</summary>

It is a type of an **Access Control Vulnerability**.

* *An Access Control Vulnerability is when an attacker can gain access to information or actions not intended for them*.

An **IDOR** vulnerability can occur when a web server receives user-supplied input to retrieve objects (files, data, documents), and **too much trust** has been placed on that input data, and the web application does not validate whether the user should, in fact, have access to the requested object.

</details>

## Find and Exploit

![Changing the id value can show us personal infos about other users (IDOR)](https://2862490475-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FCKp14jVUu79ovRyJ9YuQ%2Fuploads%2Fgit-blob-0726729e050aafc7a1823be8d509c911a9827bb2%2Fimage.png?alt=media)

### **Post Variables**

Examining the contents of forms on a website can sometimes reveal fields that could be vulnerable to IDOR exploitation.

For instance, the following HTML code for a form that updates a user's password :

![](https://2862490475-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FCKp14jVUu79ovRyJ9YuQ%2Fuploads%2Fgit-blob-42113fe2e91b3ab6e36c41c31cc1fccbfedc0409%2Fimage.png?alt=media)

### **Cookies**

![Cookie value changed to 5](https://2862490475-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FCKp14jVUu79ovRyJ9YuQ%2Fuploads%2Fgit-blob-88c1cbe3485211c77feeef6d9e6ac4d4d932f0e4%2Fimage.png?alt=media)

{% embed url="<https://portswigger.net/web-security/access-control/idor>" %}
More
{% endembed %}
