Mass Assignment Attacks
API3-Broken Object Property Level Authorization (BOPLA)
Testing Account Registration for Mass Assignment in API Security
Intercepting and Testing Account Registration for Mass Assignment in crAPI
1. Intercept Account Registration Request
Intercept Account Registration Request Intercepted Request
2. Send Request to Repeater
Send Request to Repeater
3. Test for Mass Assignment
Test for Mass Assignment
4. Use Intruder for Further Testing
Use Intruder for Further Testing
Fuzzing for Mass Assignment with Param Miner
Param Miner Installation Configure Param Miner Param Miner Output
Other Mass Assignment Vectors
Hunting for Mass Assignment
Hunting for Mass Assignment Duplicate Requests
Last updated