blabla1337 / skf-labs

Repo for all the OWASP-SKF Docker lab examples
Apache License 2.0
439 stars 201 forks source link

kbid-44-authorisation-missing is not a session prediction attack #86

Closed ctxhamza closed 4 years ago

ctxhamza commented 4 years ago

the content on kbid-44-authorisation-missing refers to session prediction! but there is no session and the attack is more of idor attack

blabla1337 commented 4 years ago

@ctxhamza You are correct, its actually a form of bypass so I renamed the lab and title. Thank you for the feedback