Cybersecurity Agencies Warn Against IDOR Bugs Exploited for Data Breaches

Share:

Cybersecurity agencies in Australia and the U.S. have published a joint cybersecurity advisory warning against security flaws in web applications that could be exploited by malicious actors to orchestrate data breach incidents and steal confidential data.

This includes a specific class of bugs called Insecure Direct Object Reference (IDOR), a type of access control flaw that occurs when an application utilizes user-supplied input or an identifier for direct access to an internal resource, such as a database record, without any additional validations.

A typical example of an IDOR flaw is the ability of a user to trivially change the URL (e.g., https://example[.]site/details.php?id=12345) to obtain unauthorized data of another transaction (i.e., https://example[.]site/details.php?id=67890).

IDOR vulnerabilities are access control vulnerabilities enabling malicious actors to modify or delete data or access sensitive data by issuing requests to a website or a web application programming interface (API) specifying the user identifier of other, valid users, the agencies said. These requests succeed where there is a failure to perform adequate authentication and authorization checks.

The authoring entities – the Australian Signals Directorate’s Australian Cyber Security Centre (ACSC), the U.S. Cybersecurity and Infrastructure Security Agency (CISA), and the U.S. National Security Agency (NSA) – noted that such flaws are being abused by adversaries to compromise the personal, financial, and health information of millions of users and consumers.

To mitigate such threats, it’s recommended that vendors, designers, and developers adopt secure-by-design and -default principles and ensure software performs authentication and authorization checks for every request that modifies, deletes, and accesses sensitive data.

The development comes days after CISA released its analysis of data gathered from risk and vulnerability assessments (RVAs) conducted across multiple federal civilian executive branch (FCEB) as well as high-priority private and public sector critical infrastructure operators.

The study found that Valid Accounts were the most common successful attack technique, responsible for 54% of successful attempts, followed by spear-phishing links (33.8%), spear-phishing attachments (3.3%), external remote services (2.9%), and drive-by compromises (1.9%).

Legitimate accounts, which could either be former employee accounts that have not been removed from the active directory or default administrator accounts, have also emerged as the top vector for establishing persistence in a compromised network (56.1%), escalating privileges (42.9%), and defense evasion (17.5%).

To guard against the successful Valid Accounts technique, critical infrastructure entities must implement strong password policies, such as phishing-resistant [multi-factor authentication], and monitor access logs and network communication logs to detect abnormal access, CISA said.

 

(c) Thin

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
10:15 pm, May 31, 2025
weather icon 19°C
L: 18° | H: 20°
overcast clouds
Humidity: 75 %
Pressure: 1014 mb
Wind: 9 mph SW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 99%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:49 am
Sunset: 9:06 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 10:00 pm
weather icon
18° | 20°°C 0.2 mm 20% 15 mph 82 % 1015 mb 0 mm/h
Mon Jun 02 10:00 pm
weather icon
11° | 21°°C 0 mm 0% 12 mph 82 % 1019 mb 0 mm/h
Tue Jun 03 10:00 pm
weather icon
11° | 18°°C 1 mm 100% 15 mph 93 % 1013 mb 0 mm/h
Wed Jun 04 10:00 pm
weather icon
9° | 18°°C 0.48 mm 48% 12 mph 81 % 1011 mb 0 mm/h
Thu Jun 05 10:00 pm
weather icon
11° | 15°°C 1 mm 100% 16 mph 94 % 1011 mb 0 mm/h
Tomorrow 1:00 am
weather icon
15° | 18°°C 0 mm 0% 8 mph 76 % 1014 mb 0 mm/h
Tomorrow 4:00 am
weather icon
13° | 15°°C 0 mm 0% 8 mph 82 % 1015 mb 0 mm/h
Tomorrow 7:00 am
weather icon
13° | 13°°C 0 mm 0% 10 mph 75 % 1015 mb 0 mm/h
Tomorrow 10:00 am
weather icon
17° | 17°°C 0 mm 0% 11 mph 45 % 1015 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
20° | 20°°C 0 mm 0% 12 mph 37 % 1014 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
20° | 20°°C 0 mm 0% 15 mph 39 % 1013 mb 0 mm/h
Tomorrow 7:00 pm
weather icon
18° | 18°°C 0.2 mm 20% 11 mph 57 % 1014 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
15° | 15°°C 0 mm 0% 8 mph 72 % 1015 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,377.75
0.13%
Ethereum(ETH)
€2,242.07
-1.37%
Tether(USDT)
€0.88
0.02%
XRP(XRP)
€1.94
0.19%
Solana(SOL)
€138.80
-1.70%
USDC(USDC)
€0.88
-0.01%
Dogecoin(DOGE)
€0.171447
-2.63%
Shiba Inu(SHIB)
€0.000011
-2.02%
Pepe(PEPE)
€0.000011
-7.84%
Peanut the Squirrel(PNUT)
€0.231575
-0.92%
Scroll to Top