WeAreDevelopers LIVE Oct 12, 2020

How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR

Anna Bacher

Could a simple URL tweak expose your database? IDOR vulnerabilities routinely cause massive enterprise data breaches. Learn to systematically eradicate these flaws using AI-driven secure coding.

Pause
Mute Enter Fullscreen
#1 about 4 min

Introduction to insecure direct object reference vulnerabilities

How software vulnerabilities like IDOR enable massive data breaches by breaking access controls.

#2 about 3 min

Real-world business consequences of IDOR vulnerabilities

Why IDOR exploitation causes severe business consequences like account takeovers and heavy financial penalties.

#3 about 2 min

Mechanisms of exploiting IDOR through URL manipulation

How attackers gain unauthorized access to sensitive documents by simply incrementing ID numbers in web requests.

#4 about 4 min

Setting up a penetration testing environment for web apps

To safely demonstrate web application vulnerabilities, developers can prepare an environment using Kali Linux and Burp Suite.

#5 about 5 min

Exploiting e-commerce basket identifiers with Burp Suite

Attackers can intercept and manipulate API requests using Burp Suite to access other users' shopping baskets without authorization.

#6 about 7 min

Modifying user product reviews via IDOR vulnerability exploitation

Modifying user identifiers in intercepted HTTP requests allows attackers to impersonate users and alter product reviews.

#7 about 3 min

Reviewing high-profile IDOR vulnerabilities found on HackerOne

Analyzing real IDOR exploits in major platforms reveals how simple API oversight leads to massive account takeovers.

#8 about 2 min

Challenges of systematically defending enterprise code against IDOR

Because traditional mitigation strategies rely heavily on manual access controls, they often fail to protect enterprise codebases.

#9 about 7 min

Detecting complex IDOR vulnerabilities using code property graphs

Analyzing source code through multi-graph structures helps developers identify complex IDOR patterns with fewer false positives.

#10 about 3 min

Limitations of CodeQL for accurate IDOR vulnerability detection

Standard semantic query tools often miss critical vulnerabilities by relying too heavily on rigid variable naming conventions.

#11 about 5 min

Improving detection and automated patching with neural networks

Training neural networks on code property graphs empowers developers to automatically detect vulnerabilities and generate authorization patches.

Matching moments

5:30 min

Identifying non-coding software vulnerabilities and organizational risks

Tino Sokic · WWC 2023

2:55 min

Identifying common and emerging application injection attack vectors

Bozidar Spirovski Bozidar Spirovski +1 · Coffee With Developers

3:06 min

Transitioning from code risks to data-driven business threats

Jon Geater · WWC 2023

1:08 min

Mitigating AI code risks and OWASP recommendations

Liran Tal Liran Tal · LIVE

2:10 min

Examining common exploitation techniques against software organizations

Vandana Verma · LIVE

4:48 min

Using intentionally vulnerable applications for practical security training

Bozidar Spirovski Bozidar Spirovski +1 · Coffee With Developers

Upcoming sessions on this topic

Open session

World Congress 2026 North America

Know Your Enemies: Live Exploit of a PHP Engine Security Breach

Alexandre Daubois

CTO of Les-Tilleuls.coop / Symfony Core Team / PHP & FrankenPHP Core Maintainer

Alexandre Daubois
Open session

World Congress 2026 North America

Secure-by-Inclusion: Preventing Accessibility Barriers from Becoming Security Vulnerabilities

Radostina (Ina) Tsvetkova

Norwegian Directorate of Labour and Welfare (NAV), Senior Advisor in Digital Accessibility and Inclusive Design

Radostina (Ina) Tsvetkova
Open session

World Congress 2026 North America

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy
Open session

World Congress 2026 North America

Don’t kill my Vibes - Simple Steps to Stay Secure when Vibe Coding

Isaac Evans

Co-founder & CEO of Semgrep

Isaac Evans
Open session

World Congress 2026 North America

SecurePrompt: Building a Pre-Flight Security Layer for Agentic AI

Ravi Sastry Kadali

AI/ML Engineer at General Motors

Ravi Sastry Kadali
Open session

World Congress 2026 North America

The Things Your AI Isn't Telling You

Desmond Lamptey

Lead Software Engineer @ Capital One

Desmond Lamptey