Broken Access Control | Complete Guide

2024 ж. 16 Мам.
39 655 Рет қаралды

In this video, we cover the theory behind Access Control vulnerabilities, how to find these types of vulnerabilities from both a white box and black box perspective, how to exploit them and how to prevent them.
▬ ✨ Support Me ✨ ▬▬▬▬▬▬▬▬▬▬
Buy my course: bit.ly/30LWAtE
▬ 📖 Contents of this video 📖 ▬▬▬▬▬▬▬▬▬▬
00:00 - Introduction
00:28 - Web Security Academy Course (bit.ly/30LWAtE)
01:39 - Agenda
02:25 - What is Broken Access Control?
22:50 - How to Find Access Control Vulnerabilities?
30:29 - How to Exploit Access Control Vulnerabilities?
34:40 - How to Prevent Access Control Vulnerabilities?
39:00 - Resources
39:15 - Thank You
▬ 🔗 Links 🔗 ▬▬▬▬▬▬▬▬▬▬
Video slides: github.com/rkhal101/Web-Secur...
Web Security Academy OS Command Injection: portswigger.net/web-security/...
Cross-Origin Resource Sharing Playlist: • Cross-Origin Resource ...
Rana's Twitter account: / rana__khalil
Hacker Icons made by Freepik: www.freepik.com

Пікірлер
  • 📚📚 Don't want to wait for the weekly release schedule to gain access to all the videos and want to be added to a discord server where you can ask questions? Make sure to sign up to my course: bit.ly/30LWAtE

    @RanaKhalil101@RanaKhalil101 Жыл бұрын
  • I know about you for a while now, just started with your videos , but I have to say you are one amazing teacher. Your soft voice and deep knowledge of the subject makes it a lot easier for me. Thank you so much. I will definitely buy your courses.

    @Stephanus21@Stephanus21 Жыл бұрын
  • Thank you for the work you've put into making this 🙏🏾

    @1990shahid@1990shahid Жыл бұрын
  • This is gold! I've understood many concepts and solved 40+ labs on the academy website, thanks to your content. I think I won't miss any single video on this channel! Wish you all the best ❤❤❤

    @user-gn7hh3zw6n@user-gn7hh3zw6n5 ай бұрын
  • يعجبني حماسك والمثابرة شكرا على هذا الشرح

    @snowden-IT@snowden-IT Жыл бұрын
  • Nobody teach as good as you, you make this thing easy to learn thanks Rhana❤

    @gangsternerd8419@gangsternerd8419 Жыл бұрын
  • This is my first video, I understood everything and I can't wait for the practical explanation شكرا

    @hdammotowa9695@hdammotowa9695 Жыл бұрын
  • Simple and forward , Thanks!

    @maakthon5551@maakthon5551 Жыл бұрын
  • really well explained ✌🏽

    @Axel-rs3cg@Axel-rs3cg9 ай бұрын
  • I love your videos they're so helpful :)

    @MFoster392@MFoster392 Жыл бұрын
  • Brilliant !!

    @balasubramaniamgopal8437@balasubramaniamgopal84379 ай бұрын
  • Chokrane Bzaff ! Thank You so much !

    @xbaleks4609@xbaleks4609 Жыл бұрын
  • La explicación es muy clara, excelente video 🌄🌠😉🇨🇴🇨🇴

    @Davidgonzalez-tp4ew@Davidgonzalez-tp4ew Жыл бұрын
  • Thank You for doing this

    @sintayehutsegayeworku1855@sintayehutsegayeworku1855 Жыл бұрын
  • yes make plz a bonus video about this topic!! thanks

    @MrBlackhats@MrBlackhats Жыл бұрын
  • Thank you❤

    @Love-yv1fc@Love-yv1fc Жыл бұрын
  • great video. will you upload ctf examples?

    @css2165@css2165 Жыл бұрын
  • thank you ❤❤

    @mohamedmahrous9500@mohamedmahrous9500 Жыл бұрын
  • Great vid...Just revised this vuln.

    @shayansec@shayansec Жыл бұрын
  • Thank you mam for such informative videos

    @riteshasthana7824@riteshasthana78244 ай бұрын
  • Thanks those videos ❤❤

    @brudora3096@brudora3096 Жыл бұрын
  • Thank you Hana

    @paulojr1384@paulojr1384 Жыл бұрын
  • Am totally new for IT field, am accountant in the banking industry. But now am learning computer science to be a hacker. I first see you in "David Bombal" KZhead channel interview and now am your follower. Thank You for Doing This (I really want to buy your course but I can't I am in Ethiopia.

    @sintayehutsegayeworku1855@sintayehutsegayeworku1855 Жыл бұрын
  • Rana I love your content hope you all best What about the OSWE , and your progress ? Have you size it ?

    @kanimani8226@kanimani8226 Жыл бұрын
  • Its really good...👍👍keep it up..

    @gajendraupadhyay6740@gajendraupadhyay6740 Жыл бұрын
  • thanksyou for the valueable content

    @Donut-qt9mr@Donut-qt9mr10 ай бұрын
  • Finally Ur back again and on time cause i finish my finals soon 🥰

    @ahmedmouad344@ahmedmouad344 Жыл бұрын
  • Thank you

    @FaultyGlitch@FaultyGlitch11 ай бұрын
  • thanks

    @amin_alaa@amin_alaa11 ай бұрын
  • Hi Rana, Want to see how you are using Autorize in burpsuite to check for access contorl bypass

    @lifeofsq5653@lifeofsq56537 ай бұрын
  • i like you'r vedios. thanks Mrs

    @suyunovjasurbek@suyunovjasurbekАй бұрын
  • please make a video on the extension.🙏

    @rahulgogra7089@rahulgogra708910 ай бұрын
  • Great job, Thank you from 🇵🇰

    @user-rs3nv6yu7s@user-rs3nv6yu7s Жыл бұрын
  • in fact is that I find it difficult to understand everything cuz my English skills are not perfect, but I do my best, and u still the number one to me tho .. so thx so much ma teacher تحية اليك من الجزائر .

    @mohmino4532@mohmino45325 ай бұрын
  • So access control is like permissions????

    @TheBlackmanIsGod@TheBlackmanIsGod8 ай бұрын
  • Could u upload whole videos which comes under "Access Control vulnerabilities"?

    @tnt7298@tnt7298 Жыл бұрын
  • perfection

    @css2165@css2165 Жыл бұрын
  • Love u sister please how to use autorize

    @Shintowel@Shintowel Жыл бұрын
  • Love from by heart

    @chowdhurytowhidahmed7780@chowdhurytowhidahmed7780 Жыл бұрын
  • @rana khalil. 19:58 on this video, it is not vulnerable at all. I will tell the implementations. 1) Every request comes through a middleware which checks the jwt. if the jwt is altered, they will never get this function. since we are getting the id from jwt, we can ensure that the request comes from the owner of the the account. if someone altered id field of jwt, middleware return the request. hope you get it.

    @nibrasmuhammed5105@nibrasmuhammed5105 Жыл бұрын
    • No. How does authentication middleware prevents attacker to exploit this piece of code? Even if I am authenticated as user1 and order with id 2 (for example) was created by user2, I still can make a DELETE request to /orders/2/ and delete that order, because there was no access control in that piece of code

      @UpTheStack@UpTheStack Жыл бұрын
    • @@UpTheStack talking about IDOR?

      @nibrasmuhammed5105@nibrasmuhammed5105 Жыл бұрын
  • يعطيكي العافية انسة رنا يا ريت تعملي فيديوهات بالعربي وشكرا

    @rolamahmoud9678@rolamahmoud9678 Жыл бұрын
  • Where can I use the lab is it free?????

    @sakura-gd8nh@sakura-gd8nh2 күн бұрын
  • think you sister you the best

    @saadeddine6418@saadeddine6418 Жыл бұрын
  • Mashalla sesiter

    @CRYSTAL-fd4fw@CRYSTAL-fd4fw3 ай бұрын
  • 🤘🏻👌

    @Matinirx@Matinirx Жыл бұрын
  • Please make web hacking course for udemy

    @noorrehman6344@noorrehman6344 Жыл бұрын
  • Thanks from 🇮🇱✌️

    @omarkalom1962@omarkalom1962 Жыл бұрын
  • يا لو الشرح ده بالعربي

    @omarmostafa543@omarmostafa5435 ай бұрын
  • bring back cortex

    @ctc8998@ctc89982 ай бұрын
  • Kindly update theic or speak louder please

    @sayantandatta2996@sayantandatta29968 ай бұрын
  • :)

    @TheCyberWarriorGuy@TheCyberWarriorGuy Жыл бұрын
KZhead