Table of Contents
Insecure direct object references IDOR
1: Register your account on PortSwigger.
Website: https://portswigger.net/users/register
2: Open the Lab: Insecure direct object references.
Website: https://portswigger.net/web-security/access-control/lab-insecure-direct-object-references
3: Access the LAB.

4: Select the Live chat tab.

5: Open the Burp Suite.
6: On the Intercept.
7: Second, a message, and then select View transcript.

8: Refresh the Live Chat page.
Shortcut key: f5
9: View the transcript.
10: Send to the Repeater.
Shortcutkey: ctrl + r

11: Send the data.

12: Follow the redirection.

13: Change the Parameter and find the password.
Note: Remove the 3.txt and add the 1.txt.

14: The password is?
Password: hl86m5x4uyvuai88ox6p
15: Off the Intercept.
16: Log in to the account.
17: The Username and Password?

Username: carlos
Password: hl86m5x4uyvuai88ox6p
18: The LAB has been completed.
