logo

Finding Access Control Vulnerabilities with Autorize

ID: 8b442870-1c4a-5778-945b-6bd1f3fb1216

STIX ID: report--8b442870-1c4a-5778-945b-6bd1f3fb1216

Feed Name: Black Hills Infosec Blog

Threat Score
25/100

Date Published: 2024-11-21

Date Updated: 2026-04-27

Author: BHIS

...
...

This blog post demonstrates how to use the Burp Suite Autorize extension to detect broken access controls (vertical and horizontal) in web applications. Using OWASP Juice Shop, the author shows how to identify session tokens, minimize requests to the essential token, configure Autorize to replay requests under different authentication contexts, and discover an insecure direct object reference (IDOR) that allows retrieval of other users' shopping baskets; the article serves as a practical tutorial for penetration testers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.