IDOR with advanced parameter manipulation techniques
This lab demonstrates advanced IDOR vulnerabilities using various parameter manipulation techniques. The application implements different methods of parameter handling that can be bypassed using creative manipulation techniques.
Objective: Use advanced parameter manipulation techniques to bypass IDOR protections and access unauthorized data.
// Advanced parameter manipulation techniques
switch ($technique) {
case 'basic':
// Basic IDOR - direct parameter manipulation
if ($param1 && isset($data_sources['users'][$param1])) {
$data = $data_sources['users'][$param1];
}
break;
case 'encoded':
// Encoded parameter manipulation
$decoded_param = base64_decode($param1);
if ($decoded_param && isset($data_sources['users'][$decoded_param])) {
$data = $data_sources['users'][$decoded_param];
}
break;
case 'hash':
// Hash-based parameter manipulation
if ($param1) {
$hash = md5($param1);
// Simulate hash-based lookup
}
break;
case 'json':
// JSON parameter manipulation
if ($param1) {
$json_data = json_decode($param1, true);
if ($json_data && isset($json_data['id'])) {
$data = $data_sources['users'][$json_data['id']];
}
}
break;
}