Manuals / Security Testing Basics / Chapter 2

A · Common flaws · beginner · ~35 min · Chapter 2 of 5

Auth & session basics

Broken auth and session mishandling are still everyday bugs. Test logout, expiry, and privilege.

Path progress
40%

Step 1 of 1

Horizontal privilege

Can user A see user B’s resource by changing an ID?

Horizontal privilegeDrag stickies · tap for tips
Study mapDrag stickies · tap for tipsKeep it shortdrag · tap →Name the waitdrag · tap →Scope locatorsdrag · tap →Trace when stuckdrag · tap →One browser firstdrag · tap →Isolate statedrag · tap →Assert the UIdrag · tap →Retry wiselydrag · tap →Seed datadrag · tap →Close the loopdrag · tap →Keep it shortdrag · tap →Name the waitdrag · tap →Scope locatorsdrag · tap →Trace when stuckdrag · tap →One browser firstdrag · tap →Isolate statedrag · tap →Pathwise hackdrag · tap →Horizontal priviledrag · tap →Try thisdrag · tap →Follow the dashed drag · tap →

Do this now

Attempt one IDOR-style check on a safe staging app.

Pro tip: Never test production with destructive payloads.

Was this step clear?
Chapter learning outcomes
  • Session fixation smells
  • Logout reality
  • Role checks

Clear these before you leave