Skip to main content
This page aggregates cross-platform resources to practice Access Control / IDOR: retired Hack The Box machines, PortSwigger Web Security Academy labs and TryHackMe rooms, plus curated resources (HackTricks, PortSwigger, etc.) and related skills. Coverage: 24 challenges across 3 platforms — 1 HackTheBox · 14 PortSwigger · 9 TryHackMe. 1 with a Spanish writeup, 3 with a video writeup.

Where to start

Ordered by actual difficulty. At the same level: isolated lab first, then the guided room, and the full machine last.
  1. PortSwiggerBypassing access controls using email address parsing discrepancies (Apprentice) · 🇬🇧
  2. PortSwiggerInsecure direct object references (Apprentice) · 🇬🇧
  3. PortSwiggerUnprotected admin functionality (Apprentice) · 🇬🇧
  4. PortSwiggerUnprotected admin functionality with unpredictable URL (Apprentice) · 🇬🇧
  5. PortSwiggerUser ID controlled by request parameter (Apprentice) · 🇬🇧
  6. PortSwiggerUser ID controlled by request parameter with data leakage in redirect (Apprentice) · 🇬🇧 📹

Curated resources

HTB machines practicing Access Control / IDOR (1)

PortSwigger labs practicing Access Control / IDOR (14)

TryHackMe rooms practicing Access Control / IDOR (9)


Back to the full glossary Last updated: 2026-08-17