Penetration Testing on Web Application Using Insecure Direct Object References (IDOR) Method

I. Pratama, Alvin Maulana Rhusuli
{"title":"Penetration Testing on Web Application Using Insecure Direct Object References (IDOR) Method","authors":"I. Pratama, Alvin Maulana Rhusuli","doi":"10.1109/ICISS55894.2022.9915074","DOIUrl":null,"url":null,"abstract":"Security on a network is a crucial aspect along with the increase in the amount of data exchanged on the internet network. Every company or organization is required to be able to always maintain the confidentiality, integrity, and authentication of data on a web application according to international security standards. This is partly due to the increasing dependence of the community on a web application so that the overall security of the system must always be measured and improved. This paper examines the weaknesses and vulnerabilities of the web application by penetration testing using a method in the form of Insecure Direct Object References (IDOR), with a case study using one URL contained in the application. The test results obtained are the tested URLs then show vulnerabilities to Insecure Direct Object References (IDOR).","PeriodicalId":125054,"journal":{"name":"2022 International Conference on ICT for Smart Society (ICISS)","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-08-10","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2022 International Conference on ICT for Smart Society (ICISS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICISS55894.2022.9915074","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

Security on a network is a crucial aspect along with the increase in the amount of data exchanged on the internet network. Every company or organization is required to be able to always maintain the confidentiality, integrity, and authentication of data on a web application according to international security standards. This is partly due to the increasing dependence of the community on a web application so that the overall security of the system must always be measured and improved. This paper examines the weaknesses and vulnerabilities of the web application by penetration testing using a method in the form of Insecure Direct Object References (IDOR), with a case study using one URL contained in the application. The test results obtained are the tested URLs then show vulnerabilities to Insecure Direct Object References (IDOR).
基于不安全直接对象引用(IDOR)方法的Web应用渗透测试
随着互联网上交换的数据量的增加,网络的安全性是一个至关重要的方面。每个公司或组织都需要能够根据国际安全标准始终维护web应用程序上数据的机密性、完整性和身份验证。这部分是由于社区对web应用程序的依赖性越来越大,因此必须始终测量和改进系统的整体安全性。本文通过使用不安全直接对象引用(IDOR)形式的方法进行渗透测试,并使用应用程序中包含的一个URL进行案例研究,来检查web应用程序的弱点和漏洞。获得的测试结果是测试的url,然后显示不安全直接对象引用(IDOR)的漏洞。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信