4 ms·
> you could request somebody's data by just passing different id in url Developers should feed their models the OWASP Website. This is known as IDOR. https://c
by one33seven 3mo ago
> you could request somebody's data by just passing different id in url
Developers should feed their models the OWASP Website. This is known as IDOR.
https://cheatsheetseries.owasp.org/cheatsheets/Insecure_Direct_Object_Reference_Prevention_Cheat_Sheet.html https://cheatsheetseries.owasp.org/cheatsheets/Insecure_Dire...
- avdept 3mo agodevelopers do(but honestly devs are much more rarely do these mistakes) non-devs have no idea about security at all, except that they need login page lol