Where to start
Ordered by actual difficulty. At the same level: isolated lab first, then the guided room, and the full machine last.- PortSwigger — Bypassing access controls using email address parsing discrepancies (Apprentice) · 🇬🇧
- PortSwigger — Insecure direct object references (Apprentice) · 🇬🇧
- PortSwigger — Unprotected admin functionality (Apprentice) · 🇬🇧
- PortSwigger — Unprotected admin functionality with unpredictable URL (Apprentice) · 🇬🇧
- PortSwigger — User ID controlled by request parameter (Apprentice) · 🇬🇧
- PortSwigger — User ID controlled by request parameter with data leakage in redirect (Apprentice) · 🇬🇧 📹
Curated resources
HTB machines practicing Access Control / IDOR (1)
PortSwigger labs practicing Access Control / IDOR (14)
TryHackMe rooms practicing Access Control / IDOR (9)
← Back to the full glossary Last updated: 2026-08-17