Documentation
README
IDOR Automated Testing
Objective
Systematically test all API endpoints for Insecure Direct Object Reference vulnerabilities using two accounts with different privilege levels.
Testing Methodology
Phase 1: Set Up Two Accounts
- Account A (victim) — owns resources being tested
- Account B (attacker) — tries to access Account A's resources
Phase 2: Automated Cross-Account Testing
This is the opening of the README. Read the full README on GitHub.