idor-methodology
Audited by Socket on Apr 22, 2026
3 alerts found:
Securityx3This fragment is an offensive IDOR exploitation and enumeration guide with an automation snippet that harvests object identifiers from protected APIs using a supplied Bearer token and supports chaining those identifiers into further unauthorized queries (REST and GraphQL, plus storage/object access and upload-path testing). It does not show classical embedded malware behaviors (no persistence/stealth/system compromise in the snippet itself), but it is highly weaponizable and would represent a significant security risk if included in a dependency, because it directly enables authorization bypass and potential sensitive data exposure or state changes when used against vulnerable targets.
This fragment is an offensive IDOR authorization-bypass guide and automation harness. It systematically constructs and sends authenticated, attacker-controlled HTTP requests (methods/paths/encodings/Content-Type/HPP/type-confusion-like payloads and related header concepts) and uses response codes to infer potential authorization bypasses. It does not exhibit classic malware capabilities, but its abuse-oriented functionality makes it a high security-risk artifact for supply-chain inclusion.
该技能不是普通文档助手,而是面向 AI 代理的漏洞利用方法论,专门教授越权测试、绕过鉴权、读取他人数据及写操作提权。虽然未见可疑安装源、凭据窃取或外部数据回传,但其能力范围与“exploit”定位一致且本身属于高风险 offensive-security 技能,应归类为 SUSPICIOUS 而非确认恶意。