📋 What Is It?
Broken Access Control - Restrictions on what authenticated users are allowed to do are often not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data.
#5
OWASP Rank 2017
5%
Apps Tested
144K
Occurrences
⚠️ Common Exploits
- Direct Object Reference: Access other users' data
- Forced Browsing: Access restricted pages
- Missing Function Level Access Control: Call admin APIs
- Parameter Tampering: Modify authorization parameters
- Elevation of Privilege: Gain higher access level
🔴 Attack Flow
1. Attacker logs in as regular user
↓
2. Discovers admin functionality in HTML source
↓
3. Directly accesses admin endpoints
↓
4. Server fails to verify authorization
↓
5. BREACH: Admin access granted!
↓
2. Discovers admin functionality in HTML source
↓
3. Directly accesses admin endpoints
↓
4. Server fails to verify authorization
↓
5. BREACH: Admin access granted!
✓ Prevention Checklist
- Deny by default, except for public resources
- Implement server-side access control checks
- Use centralized authorization mechanism
- Log access control failures and alert admins
- Invalidate JWT tokens on server after logout
📌 Quick Reference
Risk Level: CRITICAL RISK
Year: OWASP Top 10 2017
Category: WEB
Ranking: #5 in 2017