👑Find IDOR (CWE-639)
Load PwnFox.jar File Burp to User Based highlight in burp
Create 2 Containers with Pwnfox Browser Extention
Create 2 Accounts Attacker Account and Victim Account
login Attacker Account and Victim Account
Open Autorize Extention in Burp-suite
And Paste Cookie/JWT Value with Header
and Add filters
(1) Scope items only
(2) URL Not Contains (simple String): socket.io
(3) URL Contains (regex): .+/api/.+
then tick Auto Scroll Check Box
Click Autorize Box on
then Manuly Chek Authorization and Authentication and Privilidge Access Funtions on Victim Accoun and With See the Result on Autorize TAB
Last updated