Education logo

How i found 60 IDOR vulnerabilities in UK government websites within 24h

bug bounty poc

By X84Published 2 years ago • 3 min read
IDOR

Hello hackers, this is X84. I hope this post finds you well. Today, I’m excited to share a fascinating write-up about a recent discovery I made: identifying over 60 Insecure Direct Object Reference (IDOR) vulnerabilities across UK government websites within just 24 hours. Let’s dive into what IDOR is, how I found these vulnerabilities, and the impact of my findings.

What is an IDOR vulnerability?

Insecure Direct Object References (IDOR) are a type of access control vulnerability that occurs when an application allows users to directly access objects using their input. This vulnerability arises when developers expose internal objects, such as files or database entries, associated with specific users without proper validation. Attackers can exploit these insecure references to gain unauthorized access to sensitive data.

IDOR

Example:

An IDOR vulnerability is like having a library card that lets you borrow any book by simply knowing its ID number, even if the book isn’t assigned to you. Similarly, in a web application, it allows users to access or modify sensitive information by directly manipulating object identifiers, bypassing proper authorization checks.

The Discovery Process

Before diving into testing UK government websites, I had already discovered an IDOR vulnerability on a different platform. This vulnerability allowed unauthorized access to private documents, including project plans, employee degrees, and other sensitive files. Although this report was marked with high severity, it was unfortunately marked as a duplicate. Motivated by this experience, I decided to test for similar vulnerabilities on UK government sites.

To identify potential IDOR vulnerabilities, I utilized "Google dorking," a technique involving advanced search queries to locate specific endpoints or resources that might be vulnerable. By crafting targeted search queries, I was able to discover endpoints exposing files or data with direct object references.

// Some dork that i used :

site*.gov.uk inurl:file filetype:pdf

site*.gov.uk inurl:id= filetype:pdf

site*.gov.uk inurl:fileid filetype:pdf

site*.gov.uk inurl:document filetype:pdf

site*.gov.uk inurl:documentID filetype:pdf

After running these queries, I found several interesting endpoints that might be vulnerable to IDOR issues, such as:

https://example.com/ViewDocument.aspx?fileid=44994629

https://example.com/download/downloads/id/27/

https://example.com/file/5710675

https://example.com/document/149436/download

https://example.com/epps/cft/downloadInfoItem.do?documentId=2728736

Testing and Verification

I used Burp Suite Intruder to test these endpoints, validating which IDs were functional and collecting them in a separate file. Then, I created a simple Python script to download files associated with these valid IDs, as shown in the screenshot below:

python script

I manually reviewed the downloaded files to check for sensitive information. To my confirmation, I found several private files containing personal information and other sensitive government documents.

Reporting :

Within a 24-hour period, I identified 60 distinct IDOR vulnerabilities. Each of these vulnerabilities allowed unauthorized access to different resources or files, highlighting a significant security risk. The impact ranged from exposing sensitive data to unauthorized access to critical documents.

I reported all 60 findings to the UK government. I’m pleased to share that all 60 reports were marked as high severity, validating the seriousness of the vulnerabilities I discovered.

some reports

Impact:

  1. Unauthorized access to sensitive information: IDOR vulnerabilities allow attackers to access confidential data, leading to identity theft and fraud.
  2. Data breaches and privacy violations: Exploiting IDOR vulnerabilities can result in breaches that expose customer information, leading to legal consequences and privacy infringements.
  3. Reputation damage: IDOR security breaches can severely damage a company’s reputation and erode trust among stakeholders.
  4. Financial losses: Dealing with IDOR aftermath can be expensive, involving investigation costs, security measures, notifications, and potential legal actions.

Remediation:

The best way to guard against IDOR vulnerabilities is to enforce tight access control checks on each capability to determine whether the user is permitted to access / manipulate the requested object.

Thanks for reading !!! Happy Hacking !!!!

follow me on X — https://x.com/X8_4_

studentteacherhow tocourses

About the Creator

X84

too stupid to come up with a bio

Enjoyed the story? Support the Creator.

Subscribe for free to receive all their stories in your feed.

Subscribe For Free

Reader insights

Comments

There are no comments for this story

Be the first to respond and start the conversation.

Sign in to comment
    Written by X84