Back to Cheat Sheets

🛡️ Broken Access ControlOWASP 2017

OWASP WEB Top 10 2017 - #5

CRITICAL RISK

📋 What Is It?

Broken Access Control - Restrictions on what authenticated users are allowed to do are often not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data.

#5 OWASP Rank 2017
5% Apps Tested
144K Occurrences

⚠️ Common Exploits

  • Direct Object Reference: Access other users' data
  • Forced Browsing: Access restricted pages
  • Missing Function Level Access Control: Call admin APIs
  • Parameter Tampering: Modify authorization parameters
  • Elevation of Privilege: Gain higher access level

🔴 Attack Flow

1. Attacker logs in as regular user

2. Discovers admin functionality in HTML source

3. Directly accesses admin endpoints

4. Server fails to verify authorization

5. BREACH: Admin access granted!

✓ Prevention Checklist

  • Deny by default, except for public resources
  • Implement server-side access control checks
  • Use centralized authorization mechanism
  • Log access control failures and alert admins
  • Invalidate JWT tokens on server after logout

📌 Quick Reference

Risk Level: CRITICAL RISK
Year: OWASP Top 10 2017
Category: WEB
Ranking: #5 in 2017