Back to Browse

Access Control 6 | User ID controlled by request parameter, with unpredictable user IDs

1.0K views
Oct 24, 2025
4:36

Steps to solve: 1. Find carlos blog post. 2. Copy carlos's user id. Go to /my-account 3. Replace wiener user ID, with carlos user ID. This video is for Educational purposes only. https://portswigger.net/web-security/access-control https://portswigger.net/web-security/access-control/lab-user-id-controlled-by-request-parameter-with-unpredictable-user-ids Want me to train you for Practical courses and Global Certifications? or Want to hire me or our students for VAPT or SOC? Email: [email protected] Thank you for your awesome support: https://buymeacoffee.com/TORHAT Paytm: https://tinyurl.com/TORHAT Socials: Whatsapp: https://chat.whatsapp.com/JEWGrpUOqXxGYZas9901Ib?mode=wwc Linkedin: https://www.linkedin.com/mukesh-pyda/ Twitter: https://twitter.com/@OxTORHAT Telegram Group: https://t.me/+a9nwT9mdgeJhMDA1 Discord: https://discord.com/invite/caMKZRBjty Email: [email protected] #TORHAT #portswigger #Cybersecurity #EthicalHacking #HackingLab #SecurityChallenge #CTF (Capture The Flag) #Infosec #WebSecurity #CyberChallenge #BugBounty #CaptureTheFlag #HackingChallenge #HackMe #SecurityTraining #password #accesscontrol #DebugPage #bugbounty #bugbountyhunter #bugbountytips #bugbounty #bugbountyhunter #bugbountytips

Download

1 formats

Video Formats

360pmp49.4 MB

Right-click 'Download' and select 'Save Link As' if the file opens in a new tab.

Access Control 6 | User ID controlled by request parameter, with unpredictable user IDs | NatokHD