Testing For Broken Access Control

Systematically tests web applications and APIs for broken access control (OWASP A01:2021), including privilege escalation, missing function-level checks, insecure direct object references, and multi-tenant data leakage, using Burp Suite with the Authorize extension. Use during authorized penetration tests or RBAC/multi-tenant authorization audits.

gabrielmoreira Updated 17 repo stars

File contents

gabrielmoreira/agent-skills-mirror/tree/main/mirrors/repos/mukul975@Anthropic-Cybersecurity-Skills/skills/testing-for-broken-access-control commit 37f68837e9

Frequently asked questions

npx skillmds@latest add gabrielmoreira/testing-for-broken-access-control