Authorization vulnerabilities are the most common critical finding in our API penetration tests. We find them on nearly every engagement: a user changes an ID in the URL and gets back another user’s ...
I like to see my AuthN/AuthZ results in one beautifully colored table, and AuthMatrix is a great tool for this. However, I regularly click on the wrong part of a result record, that invalidates that ...
It would be AWESOME if AuthMatrix provided a third option for defining what identifies a user. There are countless times I have been on an engagement and wished i could use authmatrix to test a ...