nerdexam
CompTIA

PT0-002 · Question #421

A penetration tester is reviewing the logs of a proxy server and discovers the following URLs: https://test.comptia.com/profile.php?userid=1546 https://test.cpmptia.com/profile.php?userid=5482…

The correct answer is A. Insecure direct object reference. Insecure Direct Object Reference (IDOR) occur when an application provides direct access to objects based on user-supplied input. In the provided URLs, the userid parameter is directly data. This vulnerability can lead to unauthorized access to other users' profiles by simply…

Vulnerability discovery and analysis

Question

A penetration tester is reviewing the logs of a proxy server and discovers the following URLs:

https://test.comptia.com/profile.php?userid=1546 https://test.cpmptia.com/profile.php?userid=5482 https://test.comptia.com/profile.php?userid=3618 Which of the following types of vulnerabilities should be remediated?

Options

  • AInsecure direct object reference
  • BImproper error handling
  • CRace condition
  • DWeak or default configurations

How the community answered

(16 responses)
  • A
    94% (15)
  • B
    6% (1)

Explanation

Insecure Direct Object Reference (IDOR) occur when an application provides direct access to objects based on user-supplied input. In the provided URLs, the userid parameter is directly data. This vulnerability can lead to unauthorized access to other users' profiles by simply changing the userid parameter value. The other vulnerabilities listed (Improper error handling, Race condition, Weak or default configurations) do not directly relate to the issue demonstrated

Topics

#Insecure Direct Object Reference#Access Control#Web Application Security#Parameter Tampering

Community Discussion

No community discussion yet for this question.

Full PT0-002 Practice