Skip to content

#106 · Improved IDOR Detection in Our DAST Scanner

We’ve made some great improvements to our DAST scanner, focusing on more accurate IDOR (Insecure Direct Object References) vulnerability detection.

Why we split the IDOR check into two categories:

We’ve separated the IDOR check into two distinct categories—IDOR and IDOR User—for several important reasons:

  • General IDOR vs. User IDOR: A general IDOR vulnerability might allow unauthorized access to various types of resources (like files or records) based on their IDs. User IDOR, however, focuses on situations where one user can access another user’s private data (e.g., viewing someone else's account details). By splitting these into two categories, we can detect and address these issues more precisely.
  • Varying Severity: The severity of IDOR vulnerabilities often depends on the type of access. User-specific vulnerabilities often pose higher security risks and need to be prioritized differently. Splitting the checks ensures that each vulnerability is better contextualized, allowing for more appropriate risk management.
  • More Accurate Detection: With separate checks, we can fine-tune the detection for each scenario. For example, IDOR refers to broader object access problems, while User IDOR is focused on user-specific security risks. This leads to more accurate identification and clearer, more actionable results.

Additional Improvements:

These changes have allowed us to enhance the detection in the following areas:

Improved User-Based IDOR Detection (User1 Accessed User2’s Data):

It’s now easier to detect when one user (e.g., User1) can access another user’s data (e.g., User2) without permission. The scanner now checks that the response fingerprint (how the data is displayed or structured) remains the same when accessed by both users. If there's a mismatch, it flags this as a potential issue.

Improved ID-Based/Email-Based IDOR Detection:

For ID- and email-based vulnerabilities, the scanner now checks that responses have distinct fingerprints for each different user or account. Specifically, it requires at least three different fingerprints to ensure that responses aren’t the same for multiple users, making it easier to spot unauthorized data access.

Improved UUID-Based Fuzzing for Unsafe Generators:

UUIDs (Unique User Identifiers) are used to uniquely identify resources or users. If they are generated in an unsafe or predictable way, attackers could exploit them. We’ve improved our fuzzing process to better test UUID generation, ensuring that weak or predictable UUIDs are detected before they can be exploited.

These updates make the scanner more precise, ensuring that vulnerabilities are identified faster and more accurately!