Skip to content
AppSec Labs logo
  • Penetration Testing Services
    • Web Applications
    • SaaS & Multi-Tenant
    • APIs
    • Mobile Apps
    • AI & LLM
  • Our Methodology
    • Attacks & Tests
    • Testing modes
  • About
    • Alumni
    • The Book
  • Careers
  • Blog
  • Contact
  • עברית

Contact us

Have a question or comment? Submit your message through our contact form and a member of our team will get back to you within 24 hours.

    Authorization and Access Control

    • Home
    • Blog
    • Authorization and Access Control
    Authorization and Access Control

    Configured Is Not Enforced

    July 21, 2026 No comments yet

    AWS shipped four condition keys for DynamoDB and did not evaluate them at runtime. Your policy sat there, looked excellent in code, and did nothing.

    Authorization and Access Control

    A JWT That Trusted the Client: How One Shortcut Became Full Admin Access

    October 1, 2025 No comments yet

    A penetration test where a JWT carried the user’s role in its payload and the server trusted it. Changing one field – and an allowed alg:none – turned an ordinary user into an administrator.

    Authorization and Access Control

    A Valid Token Is Not a Permission: The OAuth Scope Nobody Checked

    September 24, 2025 No comments yet

    The Authorization Code flow was textbook. Then the server accepted any valid access token on an admin endpoint, whatever scope it carried – and I created an administrator.

    Authorization and Access Control

    “It’s GraphQL, It’s Typed, It’s Safe” – One Introspection Query Later

    July 28, 2025 No comments yet

    Introspection returned the whole schema. One mutation set isAdmin=true. The UI hid the field; the API never checked it.

    Authorization and Access Control

    They Batched Eight API Calls Into One. I Chained Three of Them Past Authorization.

    July 21, 2025 No comments yet

    A performance optimisation – one endpoint instead of eight calls. Every command was authorised on its own. Nobody had asked what happens when they run in the same request, against the same session object.

    Authorization and Access Control

    Sandwich Attacks: From Reset Password to Account Takeover

    December 18, 2024 Nathan Touati No comments yet

    Once Upon a Password Reset… You’ve just forgotten your password for a website. No big deal, you click “Forgot Password,” they send you a link, and you reset it. At the time the feature was designed, it was decided that this reset link would include a UUID token. The reasoning seemed sound—since UUIDs are unique, […]

    Search

    Categories

    • AI and LLM Security (26)
    • API Security (7)
    • Application Security (18)
    • Authorization and Access Control (11)
    • Black Box Testing (3)
    • Brute Force (1)
    • Cloud Security (13)
    • Engagements and Process (10)
    • Hacking (4)
    • Mobile Security (4)
    • Supply Chain (15)
    • White Box Testing (1)

    Recent posts

    • Somebody Wired the Darknet Into Your AI. What Could Go Wrong?
    • Configured Is Not Enforced
    • Every Week Someone Asks Me When AI Will Replace Pentesters
    AppSec Labs logo

    AppSec Labs offer rapid, modern security penetration testing, utilizing smart solutions to protect against evolving cyber threats.

    Features
    • Home
    Resources
    • Blog
    Company
    • About us
    Get in touch
    • info@appsec-labs.com
    • +972 52-433-9393

    © AppSec Labs 2026. All Rights Reserved.

    • Terms & Conditions
    • Privacy Policy