Hacker News new | ask | show | jobs
by one33seven 22 days ago
> you could request somebody's data by just passing different id in url

Developers should feed their models the OWASP Website. This is known as IDOR. https://cheatsheetseries.owasp.org/cheatsheets/Insecure_Dire...

1 comments

developers do(but honestly devs are much more rarely do these mistakes)

non-devs have no idea about security at all, except that they need login page lol