Finding authentication and authorization security bugs in web application routes

No ratings

Presented at GrrCON Cyber Security Summit and Hacker Conference 2023 by

This presentation introduces route-detect. route-detect is a command-line tool that seeks to aid security researchers and engineers in finding authentication (authn) and authorization (authz) security bugs in web application routes. These bugs are some of the most common security issues found today. The following industry standard resources highlight the severity of the issue: – 2021 OWASP Top 10 #1 – Broken Access Control – 2021 OWASP Top 10 #7 – Identification and Authentication Failures – 2019 OWASP API Top 10 #2 – Broken User Authentication – 2019 OWASP API Top 10 #5 – Broken Function Level Authorization Of course, not all authn or authz bugs occur in web application routes, but route-detect seeks to confront this pervasive class of bugs. Find route-detect here: https://github.com/mschwager/route-detect