Idor

Hunt Insecure Direct Object Reference (CWE-639) — missing authorization checks on object IDs. Covers horizontal vs vertical privilege escalation, UUID vs integer guessing, and GraphQL introspection-driven IDOR discovery.

purpleailab 7d0ebe2 5.3 KB Updated

File contents

purpleailab/decepticon/tree/main/packages/decepticon/decepticon/skills/standard/analyst/idor commit 7d0ebe285a

Frequently asked questions

npx skillmds@latest add purpleailab/idor