Logical Exploits Of Operation Beyond Authority 2023

By XiaoXin
A Bit Randomly

Main Contents

Logical Exploits Of Operation Beyond Authority

First, log in to the system with an account, and modify user parameters by capturing packets to achieve the purpose of viewing or modifying other people's accounts, and try to continuously test and exceed the authority of multiple interfaces or multi-function modules. At the same time, you need to log in with multiple accounts, analyze and compare the difference in the request parameters in the data packets of these accounts, and modify these different parameters to see if the purpose of unauthorized operation can be achieved.

The ultra vires loopholes are further divided into parallel overreach, vertical overreach and cross overreach.

- Parallel overreach: the permission type remains unchanged, but the permission ID changes
- Vertical overreach: permission ID remains the same, permission type changes
- Cross overpass: change the ID and change the authority.

