idor - Test IDOR and Broken Access Control
Tests authorized applications for IDOR and broken access control by assessing object references, privilege boundaries, API patterns, and bypass techniques.
Tags
Updated: 2026-10-01Capabilities
Typical Outputs
What this skill does
- Assess identifier formats
- Locate injection points
- Test horizontal access
- Test vertical access
- Enumerate sequential identifiers
- Test HTTP methods
- Probe API-specific patterns
- Attempt authorization bypasses
- Record engagement evidence
- Summarize confirmed vulnerabilities
Inputs
- Target application
- Authenticated session
- Second user account
- Higher-privilege user ID
- Proxy configuration
- Object-referencing endpoint
- Engagement state
Outputs
- Activation message
- Evidence files
- Discovered targets
- Credentials or tokens
- Changed access state
- Confirmed vulnerability findings
- Identified pivot paths
- Blocked item summary
Requirements
- Explicit written authorization
- Low-privilege authenticated account
- Second same-privilege account or privileged user ID
- Configured Burp Suite proxy
- Burp Autorize or AuthMatrix
- Burp Suite, ffuf, or curl
- State MCP server
