IDOR
Detection

IDOR is NOT ONLY on id

Double ID
Wildcard
Nuclei Template
Bypass 403
Bypass 403 / 401UUID
Unpredictable UUID
Extract UUIDs from waybackurls
UUID Version 1
Insecure UUIDChange the UUID value type
Mass IDOR Enumeration
Mass Enumeration
Bypassing Encoded References

Function Disclosure
Mass Enumeration
IDOR in Insecure APIs
Information Disclosure

Modifying Other Users' Details
Role in URL
Parameter pollution

Depreciated API versions

JSON globbing

APIs that use static keywords

Second-order IDOR

Account Takeover
Tools
Interesting Books
Interesting BooksResources
Last updated