Reading
PentestingHere Academy
23 Sep 2026
What it is
An IDOR (Insecure Direct Object Reference) shows up whenever an app hands you a plain id, and only checks that the id points to something real, not that it belongs to you. If you can change the id and still get a 200 with someone else's data, that's the bug.
The labs here
- DriveShare booking IDOR: the classic version. One id in the URL, no ownership check at all. Change it, see someone else's booking.
- Harborview Clinic patient messaging IDOR: two ids in play. The endpoint checks that one id belongs to the other, but never checks that either one belongs to you. A valid-looking pair from someone else's records still works.
- Meridian Wealth statement token forgery: no id to swap at all, just a "signed" access token you're supposed to trust. Look closely at how it's built. If the signature is something you can recompute yourself (a hash with no secret key mixed in), you don't need to guess anyone else's token. You can build one.