← PenTest+: assessment, evidence, and remediation
04 / 6 · 45 MIN

Web and API flaws and remediation

Identify the failed boundary and choose an appropriate control.

Concept and mechanism

Many flaws arise from confusing data with authority or syntax. SQL queries should separate values from structure through parameters. Column names and sorting can require mapping to fixed allowed identifiers because a value placeholder does not replace every language element. In APIs, authenticating a session does not automatically authorize every object. The server should evaluate identity, tenant, action, and resource. A hard-to-guess UUID reduces casual discovery but does not fix unauthorized reading when the identifier is known. Tests with two synthetic tenants can demonstrate that boundary without collecting customer information.

Guided application

In a fictional lab, user A can read B document. Fix server authorization and retest legitimate and denied access. If every response becomes an error, functionality is unavailable and testing does not establish acceptable remediation. For comments intended as plain text, use output handling appropriate to that context instead of inserting untrusted HTML. For cookie-authenticated actions, evaluate suitable CSRF protection; automatic session presence does not prove intent. In a service fetching images by URL, control destinations and redirects because validating the first hostname does not cover the effective destination. These measures address different mechanisms: HTTPS, CSP, and WAF can add protection but are not universal substitutes for parameterization, authorization, and application validation.

IN PRACTICE

A known UUID from another tenant should remain denied by the server even with a valid session.

Common pitfalls

UUID as authorization; HTML escaping as SQL defense; general errors as success; first URL as every destination.

Related topics: Scope, communication, and evidence · Reconnaissance and result interpretation · Discovery, coverage, and validation

Take this idea with you

Fix the boundary and rehearse legitimate use too.

Create account

Reference: Broken object-level authorization · PT0-003 / PenTest+ V3; objectives 3.0; launched 2024-12-17