Cybersecurity Agencies Warn Against IDOR Bugs Exploited for Data Breaches

Teilen:

Cybersecurity agencies in Australia and the U.S. have published a joint cybersecurity advisory warning against security flaws in web applications that could be exploited by malicious actors to orchestrate data breach incidents and steal confidential data.

This includes a specific class of bugs called Insecure Direct Object Reference (IDOR), a type of access control flaw that occurs when an application utilizes user-supplied input or an identifier for direct access to an internal resource, such as a database record, without any additional validations.

A typical example of an IDOR flaw is the ability of a user to trivially change the URL (e.g., https://example[.]site/details.php?id=12345) to obtain unauthorized data of another transaction (i.e., https://example[.]site/details.php?id=67890).

IDOR vulnerabilities are access control vulnerabilities enabling malicious actors to modify or delete data or access sensitive data by issuing requests to a website or a web application programming interface (API) specifying the user identifier of other, valid users, the agencies said. These requests succeed where there is a failure to perform adequate authentication and authorization checks.

The authoring entities – the Australian Signals Directorate’s Australian Cyber Security Centre (ACSC), the U.S. Cybersecurity and Infrastructure Security Agency (CISA), and the U.S. National Security Agency (NSA) – noted that such flaws are being abused by adversaries to compromise the personal, financial, and health information of millions of users and consumers.

To mitigate such threats, it’s recommended that vendors, designers, and developers adopt secure-by-design and -default principles and ensure software performs authentication and authorization checks for every request that modifies, deletes, and accesses sensitive data.

The development comes days after CISA released its analysis of data gathered from risk and vulnerability assessments (RVAs) conducted across multiple federal civilian executive branch (FCEB) as well as high-priority private and public sector critical infrastructure operators.

The study found that Valid Accounts were the most common successful attack technique, responsible for 54% of successful attempts, followed by spear-phishing links (33.8%), spear-phishing attachments (3.3%), external remote services (2.9%), and drive-by compromises (1.9%).

Legitimate accounts, which could either be former employee accounts that have not been removed from the active directory or default administrator accounts, have also emerged as the top vector for establishing persistence in a compromised network (56.1%), escalating privileges (42.9%), and defense evasion (17.5%).

To guard against the successful Valid Accounts technique, critical infrastructure entities must implement strong password policies, such as phishing-resistant [multi-factor authentication], and monitor access logs and network communication logs to detect abnormal access, CISA said.

 

(c) Thin

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
10:14 am, Mai 19, 2025
Wetter-Symbol 13°C
L: 12° | H: 14°
overcast clouds
Luftfeuchtigkeit: 75 %
Druck: 1021 mb
Wind: 7 mph E
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 5:02 am
Sonnenuntergang: 8:51 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
12° | 14°°C 0 mm 0% 12 mph 66 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
10° | 22°°C 0 mm 0% 10 mph 67 % 1022 mb 0 mm/h
Mi. Mai 21 10:00 pm
Wetter-Symbol
13° | 21°°C 0.2 mm 20% 9 mph 64 % 1020 mb 0 mm/h
Do. Mai 22 10:00 pm
Wetter-Symbol
11° | 18°°C 0 mm 0% 11 mph 64 % 1023 mb 0 mm/h
Fr. Mai 23 10:00 pm
Wetter-Symbol
7° | 18°°C 0.7 mm 70% 11 mph 77 % 1023 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
14° | 17°°C 0 mm 0% 9 mph 66 % 1021 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
17° | 19°°C 0 mm 0% 12 mph 51 % 1020 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
17° | 17°°C 0 mm 0% 10 mph 46 % 1020 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
13° | 13°°C 0 mm 0% 7 mph 61 % 1021 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
10° | 10°°C 0 mm 0% 5 mph 66 % 1022 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
10° | 10°°C 0 mm 0% 6 mph 67 % 1021 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
11° | 11°°C 0 mm 0% 7 mph 63 % 1022 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
17° | 17°°C 0 mm 0% 7 mph 46 % 1022 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€92,229.63
-0.74%
Ethereum(ETH)
€2,147.36
-4.66%
Fesseln(USDT)
€0.89
0.00%
XRP(XRP)
€2.06
-3.97%
Solana(SOL)
€144.37
-5.74%
USDC(USDC)
€0.89
0.00%
Dogecoin(DOGE)
€0.193802
-3.44%
Shiba Inu(SHIB)
€0.000013
-5.15%
Pepe(PEPE)
€0.000012
-3.65%
Peanut das Eichhörnchen(PNUT)
€0.282118
-11.82%
Nach oben scrollen