Attacking Access Control Models in Modern Web Apps
So far you may have come across various web applications where you were able to invite members with limited access to the information within the organization. Developers are able to make such applications or services by implementing access control models within their applications.
Imran Parray is the founder of Snapsec and also works as Independent Cybersecurity Researcher and Bug Bounty hunter. He spends a lot of time writing bash, Python, Automation, and tons of articles on snapsec.co/blog
In this talk we will discuss various access control measures used in modern apps, their potential shortcomings and testing methodologies.