<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Access Control on an's security blog</title><link>https://panman4040.github.io/training/portswigger/access_control/</link><description>Recent content in Access Control on an's security blog</description><generator>Hugo</generator><language>en</language><lastBuildDate>Wed, 15 Jul 2026 08:36:00 +0700</lastBuildDate><atom:link href="https://panman4040.github.io/training/portswigger/access_control/index.xml" rel="self" type="application/rss+xml"/><item><title>Referer-based access control | &lt;span style="color:#2ecc71">Apprentice&lt;/span></title><link>https://panman4040.github.io/training/portswigger/access_control/ac-apprentice6/</link><pubDate>Thu, 11 Jun 2026 15:50:16 +0800</pubDate><guid>https://panman4040.github.io/training/portswigger/access_control/ac-apprentice6/</guid><description>&lt;p>We are given the option to try out admin perms for ourselves. When we try to upgrade &lt;code>carlos&lt;/code> credentials, we can intercept the request and see what&amp;rsquo;s behind the scene:
&lt;img src="https://panman4040.github.io/images/a9a9f1d4-ae2f-4938-95ad-576445e88aba.jpg" alt="">
Unlike the previous labs, the request to elevate one&amp;rsquo;s credentials is simply a GET request. If the web app accepts &lt;code>Referer&lt;/code> arbitrarily, we can simply change the session cookie to ours and solve the lab.&lt;/p></description></item><item><title>Multi-step process with no access control on one step | &lt;span style="color:#2ecc71">Apprentice&lt;/span></title><link>https://panman4040.github.io/training/portswigger/access_control/ac-apprentice5/</link><pubDate>Thu, 11 Jun 2026 15:33:16 +0800</pubDate><guid>https://panman4040.github.io/training/portswigger/access_control/ac-apprentice5/</guid><description>&lt;p>We are given the option to try out admin perms for ourselves. When we try to upgrade &lt;code>carlos&lt;/code> credentials, there is a intermediary step that asks us to confirm our decision. Upon interception, we see that this is expressed as a param &lt;code>confirmed&lt;/code>:
&lt;img src="https://panman4040.github.io/images/799ae45f-6b32-40c0-96d0-be8a41147ba9.jpg" alt="">&lt;/p>
&lt;p>&lt;em>Hypothetically&lt;/em>, the web app may see that &lt;code>confirmed=true&lt;/code> is indeed included in the form parameters, and assumes that the person requesting this has valid credentials because they &lt;em>cannot have known&lt;/em> that third confirmation step.&lt;/p></description></item><item><title>Method-based access control can be circumvented | &lt;span style="color:#2ecc71">Apprentice&lt;/span></title><link>https://panman4040.github.io/training/portswigger/access_control/ac-apprentice4/</link><pubDate>Thu, 11 Jun 2026 13:59:16 +0800</pubDate><guid>https://panman4040.github.io/training/portswigger/access_control/ac-apprentice4/</guid><description>&lt;p>&lt;em>Took too damn long tinkering with Burp while in fact I can just paste the payload into the URL&lt;/em>&lt;/p>
&lt;p>We are given the choice to first log in the administrator account to see what&amp;rsquo;s behind the scene. While we are changing &lt;code>carlos&lt;/code> privilege, we can intercept the request:
&lt;img src="https://panman4040.github.io/images/7dac5a5c-7e49-4b38-a390-fb8eb8c54c45.jpg" alt="">
Now we know that &lt;code>/admin-roles&lt;/code> is the endpoint for changing perms, with &lt;code>username&lt;/code> and &lt;code>action&lt;/code> as its params. However when we attempt to send the POST request as &lt;code>wiener&lt;/code>, we will be hit with Method Not Allowed.&lt;/p></description></item><item><title>URL-based access control can be circumvented | &lt;span style="color:#2ecc71">Apprentice&lt;/span></title><link>https://panman4040.github.io/training/portswigger/access_control/ac-apprentice3/</link><pubDate>Thu, 11 Jun 2026 10:49:16 +0800</pubDate><guid>https://panman4040.github.io/training/portswigger/access_control/ac-apprentice3/</guid><description>&lt;p>If we are doing this blind, we can actually append the &lt;code>X-Original-URL&lt;/code> header (or equivalent) into the request and add a nonsensical endpoint, e.g. &lt;code>/asdfklsdjflks&lt;/code>. If the server gives us a Not Found, that means the backend code is processing &lt;code>X-Original-URL&lt;/code> blindly and we can insert our payload, per se.&lt;/p>
&lt;p>Thus we can add &lt;code>?username=carlos&lt;/code> into the query string, then change the &lt;code>X-Original-Url&lt;/code> path to &lt;code>/admin/delete&lt;/code>. The &lt;code>carlos&lt;/code> user will be deleted afterwards.&lt;/p></description></item><item><title>User role can be modified in user profile | &lt;span style="color:#2ecc71">Apprentice&lt;/span></title><link>https://panman4040.github.io/training/portswigger/access_control/ac-apprentice2/</link><pubDate>Thu, 11 Jun 2026 10:05:16 +0800</pubDate><guid>https://panman4040.github.io/training/portswigger/access_control/ac-apprentice2/</guid><description>&lt;p>At first, I keep digging session cookies and HTML source to see whether they contain any references of &lt;code>roleid&lt;/code> or not, and I stumped. I realised that I hadn&amp;rsquo;t even attempted to change my email to see what happens yet.&lt;/p>
&lt;p>So, upon changing our email, we can observe that the response has a JSON object that keeps tab of our username, email, and &lt;code>roleid&lt;/code>:
&lt;img src="https://panman4040.github.io/images/5ffde0b9-985d-4faa-950f-54e09d44e1e2.jpg" alt="">
Simply add &lt;code>&amp;quot;roleid&amp;quot;:2&lt;/code> into the request body and voila we will get access to the admin panel. This is a vuln called &lt;strong>Mass Assignment&lt;/strong>&lt;/p></description></item><item><title>Unprotected admin functionality with unpredictable URL | &lt;span style="color:#2ecc71">Apprentice&lt;/span></title><link>https://panman4040.github.io/training/portswigger/access_control/ac-apprentice1/</link><pubDate>Thu, 11 Jun 2026 09:38:16 +0800</pubDate><guid>https://panman4040.github.io/training/portswigger/access_control/ac-apprentice1/</guid><description>&lt;p>Very straightforward, the lab introduces a vuln where sensitive endpoints are exposed in plaintext, in this case some JS scripts:
&lt;img src="https://panman4040.github.io/images/1687fb5e-12ca-42cc-8de9-c45dc0722ced.jpg" alt="">
Simply access the hidden endpoint and we can solve the lab.&lt;/p></description></item><item><title>User role controlled by request parameter | &lt;span style="color:#2ecc71">Apprentice&lt;/span></title><link>https://panman4040.github.io/training/portswigger/access_control/user-role-controlled-by-request-parameter/</link><pubDate>Tue, 02 Jun 2026 15:00:16 +0800</pubDate><guid>https://panman4040.github.io/training/portswigger/access_control/user-role-controlled-by-request-parameter/</guid><description>&lt;p>We can simply intercept the request to &lt;code>/admin&lt;/code> and change the cookie as follow:
&lt;img src="https://panman4040.github.io/images/0b2bf73e-c606-4bf4-ad4f-e673d0c0ba56.jpg" alt="">
After that, we can delete the user &lt;code>carlos&lt;/code> and solve the lab.&lt;/p></description></item><item><title>Unprotected Admin Functionality | &lt;span style="color:#2ecc71">Apprentice&lt;/span></title><link>https://panman4040.github.io/training/portswigger/access_control/unprotected-admin-functionality/</link><pubDate>Tue, 02 Jun 2026 14:43:16 +0800</pubDate><guid>https://panman4040.github.io/training/portswigger/access_control/unprotected-admin-functionality/</guid><description>&lt;p>Just as the name implies, we are set out to look for an admin panel. Simply access &lt;code>robots.txt&lt;/code> that they convieniently left for us:
&lt;img src="https://panman4040.github.io/images/unprotected-admin-functionality.jpg" alt="">
From there we can delete the &lt;code>carlos&lt;/code> user from the server.&lt;/p>
&lt;p>Besides accessing &lt;code>robots.txt&lt;/code>, we can also utilise the Site Map feature of Burp Suite as follow:
&lt;img src="https://panman4040.github.io/images/unprotected-admin-functionality2.jpg" alt="">&lt;/p></description></item></channel></rss>