MENU

Fun & Interesting

What is Broken Access Control? A Quick Guide for Beginners

The Cyber Mentor 6,112 4 months ago
Video Not Working? Fix It Now

Interested in pursuing a TCM Security Associate or Professional-level certification? Go here to find out more: https://www.tcm.rocks/certifications-y Sponsor a Video: https://www.tcm.rocks/Sponsors Pentests & Security Consulting: https://tcm-sec.com Get Trained: https://academy.tcm-sec.com Get Certified: https://certifications.tcm-sec.com Merch: https://merch.tcm-sec.com In today's video, we dive into broken access control techniques beyond the common IDOR (Insecure Direct Object References). These are issues I've encountered in real-world applications, and we'll walk through a lab setup to demonstrate how they work. We'll also discuss how to identify and understand these vulnerabilities under the hood so you can test for them in your own security assessments. What You'll Learn in This Video: What is broken access control? A quick refresher on access control vs. authentication. Real-World Examples: Learn from practical scenarios where access control issues showed up. Lab Walkthrough: Explore two techniques to find broken access control in applications. Testing Tips: Update your notes and improve your testing strategies for similar issues moving forward. By the end of this video, you'll have a better understanding of how to spot and test for broken access control vulnerabilities, and you'll be able to expand your security testing toolkit beyond just IDOR. If you found this video helpful, don't forget to like, subscribe, and hit the notification bell to stay updated with more cybersecurity tips and training! Visit Alex's GitHub to try the challenge yourself: https://github.com/AppSecExplained #cybersecurity #infosec #hacking101 #hackingtutorial #burpsuite 📱Social Media📱 ___________________________________________ X: https://x.com/TCMSecurity Twitch: https://www.twitch.tv/thecybermentor Instagram: https://www.instagram.com/tcmsecurity/ LinkedIn: https://www.linkedin.com/company/tcm-security-inc/ TikTok: https://www.tiktok.com/@tcmsecurity Discord: https://discord.gg/tcm Facebook: https://www.facebook.com/tcmsecure Timestamps: 00:00 Broken Access Control 00:35 What is Broken Access Control? 01:15 Promo 01:39 Broken Access Control Labs 11:48 Outro 💸Donate💸 ___________________________________________ Like the channel? Please consider supporting me on Patreon: https://www.patreon.com/thecybermentor Support the stream (one-time): https://streamlabs.com/thecybermentor Hacker Books: Penetration Testing: A Hands-On Introduction to Hacking: https://amzn.to/31GN7iX The Hacker Playbook 3: https://amzn.to/34XkIY2 Hacking: The Art of Exploitation: https://amzn.to/2VchDyL The Web Application Hacker's Handbook: https://amzn.to/30Fj21S Real-World Bug Hunting: A Field Guide to Web Hacking: https://amzn.to/2V9srOe Social Engineering: The Science of Human Hacking: https://amzn.to/31HAmVx Linux Basics for Hackers: https://amzn.to/34WvcXP Python Crash Course, 2nd Edition: https://amzn.to/30gINu0 Violent Python: https://amzn.to/2QoGoJn Black Hat Python: https://amzn.to/2V9GpQk My Build: lg 32gk850g-b 32" Gaming Monitor:https://amzn.to/30C0qzV darkFlash Phantom Black ATX Mid-Tower Case: https://amzn.to/30d1UW1 EVGA 2080TI: https://amzn.to/30d2lj7 MSI Z390 MotherBoard: https://amzn.to/30eu5TL Intel 9700K: https://amzn.to/2M7hM2p G.SKILL 32GB DDR4 RAM: https://amzn.to/2M638Zb Razer Nommo Chroma Speakers: https://amzn.to/30bWjiK Razer BlackWidow Chroma Keyboard: https://amzn.to/2V7A0or CORSAIR Pro RBG Gaming Mouse: https://amzn.to/30hvg4P Sennheiser RS 175 RF Wireless Headphones: https://amzn.to/31MOgpu My Recording Equipment: Panasonic G85 4K Camera: https://amzn.to/2Mk9vsf Logitech C922x Pro Webcam: https://amzn.to/2LIRxAp Aston Origin Microphone: https://amzn.to/2LFtNNE Rode VideoMicro: https://amzn.to/309yLKH Mackie PROFX8V2 Mixer: https://amzn.to/31HKOMB Elgato Cam Link 4K: https://amzn.to/2QlicYx Elgate Stream Deck: https://amzn.to/2OlchA5 *We are a participant in the Amazon Services LLC Associates Program, an affiliate advertising program designed to provide a means for us to earn fees by linking to Amazon.com and affiliated sites.

Comment