WeAreDevelopers LIVE Oct 12, 2020

How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR

Anna Bacher

Could a simple URL tweak expose your database? IDOR vulnerabilities routinely cause massive enterprise data breaches. Learn to systematically eradicate these flaws using AI-driven secure coding.

Pause
Mute Enter Fullscreen
#1 about 4 min

Introduction to insecure direct object reference vulnerabilities

How software vulnerabilities like IDOR enable massive data breaches by breaking access controls.

#2 about 3 min

Real-world business consequences of IDOR vulnerabilities

Why IDOR exploitation causes severe business consequences like account takeovers and heavy financial penalties.

#3 about 2 min

Mechanisms of exploiting IDOR through URL manipulation

How attackers gain unauthorized access to sensitive documents by simply incrementing ID numbers in web requests.

#4 about 4 min

Setting up a penetration testing environment for web apps

To safely demonstrate web application vulnerabilities, developers can prepare an environment using Kali Linux and Burp Suite.

#5 about 5 min

Exploiting e-commerce basket identifiers with Burp Suite

Attackers can intercept and manipulate API requests using Burp Suite to access other users' shopping baskets without authorization.

#6 about 7 min

Modifying user product reviews via IDOR vulnerability exploitation

Modifying user identifiers in intercepted HTTP requests allows attackers to impersonate users and alter product reviews.

#7 about 3 min

Reviewing high-profile IDOR vulnerabilities found on HackerOne

Analyzing real IDOR exploits in major platforms reveals how simple API oversight leads to massive account takeovers.

#8 about 2 min

Challenges of systematically defending enterprise code against IDOR

Because traditional mitigation strategies rely heavily on manual access controls, they often fail to protect enterprise codebases.

#9 about 7 min

Detecting complex IDOR vulnerabilities using code property graphs

Analyzing source code through multi-graph structures helps developers identify complex IDOR patterns with fewer false positives.

#10 about 3 min

Limitations of CodeQL for accurate IDOR vulnerability detection

Standard semantic query tools often miss critical vulnerabilities by relying too heavily on rigid variable naming conventions.

#11 about 5 min

Improving detection and automated patching with neural networks

Training neural networks on code property graphs empowers developers to automatically detect vulnerabilities and generate authorization patches.

Matching moments

5:30 min

Identifying non-coding software vulnerabilities and organizational risks

Tino Sokic · World Congress 2023

2:55 min

Identifying common and emerging application injection attack vectors

Bozidar Spirovski Bozidar Spirovski +1 · Coffee With Developers

3:06 min

Transitioning from code risks to data-driven business threats

Jon Geater · World Congress 2023

1:08 min

Mitigating AI code risks and OWASP recommendations

Liran Tal Liran Tal · LIVE

2:10 min

Examining common exploitation techniques against software organizations

Vandana Verma · LIVE

4:48 min

Using intentionally vulnerable applications for practical security training

Bozidar Spirovski Bozidar Spirovski +1 · Coffee With Developers

Upcoming sessions on this topic

Open session

World Congress 2026 North America

September 24, 2026 · 14:10–14:40

Stage 2

Know Your Enemies: Live Exploit of a PHP Engine Security Breach

Alexandre Daubois

CTO of Les-Tilleuls.coop / Symfony Core Team / PHP & FrankenPHP Core Maintainer

Alexandre Daubois
Open session

World Congress 2026 North America

September 25, 2026 · 11:00–11:30

Stage 6

Secure-by-Inclusion: Preventing Accessibility Barriers from Becoming Security Vulnerabilities

Radostina (Ina) Tsvetkova

Norwegian Directorate of Labour and Welfare (NAV), Senior Advisor in Digital Accessibility and Inclusive Design

Radostina (Ina) Tsvetkova
Open session

World Congress 2026 North America

September 25, 2026 · 13:30–14:00

Stage 9

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy
Open session

World Congress 2026 North America

September 25, 2026 · 09:00–09:30

Stage 4

Don’t kill my Vibes - Simple Steps to Stay Secure when Vibe Coding

Isaac Evans

Co-founder & CEO of Semgrep

Isaac Evans
Open session

World Congress 2026 North America

September 24, 2026 · 12:15–12:45

Stage 6

AI vs. AI: Defending the open source supply chain with agentic workflows

Manfred Moser

Senior Principal DevRel Engineer at Chainguard

Manfred Moser
Open session

World Congress 2026 North America

September 25, 2026 · 15:00–17:00

Stage 12

Secure development from pull request to production with GitHub

Sam Jarvinen

Senior Solutions Engineer, GitHub

Sam Jarvinen