
Web App Privilege Escalation by 21y4d | Hack The Box hacking workshop
Source: YouTube · Hack The Box · published May 26, 2022 · 30:40
The video demonstrates how IDOR vulnerabilities can be exploited for privilege escalation in web applications through API manipulation 3:41.
Key Takeaways:
• Privilege escalation isn't limited to OS - any application with user access control is vulnerable 3:41
• IDOR vulnerability allows accessing other users' data by modifying UID parameters in API requests 7:50
• Initial attempts to change roles or create users fail due to authorization checks 9:38
• Combining information disclosure with UUID values enables modifying other users' profiles 16:08
• Fuzzing user IDs reveals an admin role ("staff admin") that can be used for privilege escalation 18:00
The presenter emphasizes this isn't just theoretical - a recent Instagram vulnerability with the same flaw earned a $50,000 bounty 22:17.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
and now it's time for our second talk and we're very happy again and honored that we have with us zayat he is a training developer for hacker box academy he was a fantastic for years uh read him for years he is also a very kind and honest person he does amazing life hacking demos we love that we had him at i think it was the unicity of stream and we had the amazing feedback so that's why we brought him back again he also released now with his team cbh and uh yeah let's do some web hacking with jiyad i'm going to answer him in the stream hello jr how are you ah we cannot hear you you are perfect yeah hey terria hey everyone hey so how do you feel that you are with us today in the stream cyber apocalypse 2 yeah very glad last time like you said we had had some good opportunity to show some s…