LAB 101 - Identifying Broken Access Control Vulnerabilities
Course Number: LAB 101
Course Duration: 5 minutes
Course CPE Credits:
Foreign Languages Available:
This lab presents a challenge in the Shadow Bank cyber range that exploits a Broken Access Control vulnerability, caused in part by missing or broken input validation and a business logic flaw. According to OWASP.org “Access control enforces policy such that users cannot act outside of their intended permissions. Failures typically lead to unauthorized information disclosure, modification or destruction of all data, or performing a business function outside of the limits of the user.
In this lab, you are an adversary acting outside of your intended permissions, attempting to sell the stock you don’t own.