Mmcp.market

offensive-idor skill

by SnailSploit·SnailSploit/Claude-Red·7.0k stars·MIT

No description in the SKILL.md.

A94/100content scan

Is the offensive-idor skill safe?

Clean: nothing in its files matched our rules. We read 1 file in the folder on 2026-09-28.

  • lowSKILL.md:1

    The name should be 1 to 64 lowercase letters, digits or hyphens.

    (missing)
  • lowSKILL.md:1

    No description, so an agent cannot tell when to use the skill.

    (missing)

Install the offensive-idor skill

A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.

git clone --depth 1 https://github.com/SnailSploit/Claude-Red.git /tmp/Claude-Red
mkdir -p ~/.claude/skills
cp -r /tmp/Claude-Red/Skills/web/offensive-idor ~/.claude/skills/offensive-idor
available in every project

In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub

The instructions your agent would load

SKILL.md as published, without the frontmatter. Read it on GitHub

SKILL: Insecure Direct Object References (IDOR)

Metadata

  • Skill Name: idor
  • Folder: offensive-idor
  • Source: https://github.com/SnailSploit/offensive-checklist/blob/main/idor.md

Description

IDOR (Insecure Direct Object Reference) testing checklist: object ID enumeration, horizontal/vertical privilege escalation, GUID predictability, indirect references via hashes, chained IDOR, and API endpoint IDOR. Use for web app pentests and bug bounty IDOR discovery.

Trigger Phrases

Use this skill when the conversation involves any of: IDOR, insecure direct object reference, horizontal privilege escalation, vertical privilege escalation, object enumeration, GUID, API IDOR, mass assignment, broken access control

Instructions for Claude

When this skill is active:

  1. Load and apply the full methodology below as your operational checklist
  2. Follow steps in order unless the user specifies otherwise
  3. For each technique, consider applicability to the current target/context
  4. Track which checklist items have been completed
  5. Suggest next steps based on findings

Full Methodology

Insecure Direct Object References (IDOR)

Shortcut

flowchart LR
    A[Create Test Accounts] --> B[Discover Features]
    B --> C[Intercept Traffic]
    C --> D[Switch IDs in Requests]
    D --> E{IDOR Found?}
    E -->|Yes| F[Document Vulnerability]
    E -->|No| G[Try Protection Bypass]
    G --> H[Monitor Information Leaks]
  • Create two accounts for each application role and designate one as the attacker account and the other as the victim account.
  • Discover features in the application that might lead to IDOR. Pay attention to features that return sensitive information or modify user data.
  • Revisit the features you discovered in step 2. With a proxy, intercept your browser traffic while you browse through the sensitive functionalities.
  • With a proxy, intercept each sensitive request and switch out the IDs that you see in the requests. If switching out IDs grants you access to other user's information or lets you change their data, this indicates an IDOR.
  • Don't despair if the application seems to be immune to IDOR. Use this opportunity to try a protection bypass technique. If the application uses an encoded, hashed, or randomized ID, you can try decoding, or predicting the IDs. You can also try supplying the application with an ID when it does not ask for one. Finally, sometimes changing the request method type or file type makes all the difference.
  • Monitor for information leaks in export files, email, and other text alerts. An IDOR now might lead to an information leak in the future.

Mechanisms

flowchart TD
    A[IDOR Vulnerabilities] --> B[Missing Authorization Checks]
    A --> C[Client-Side ID Transmission]
    A --> D[Predictable Resource Identifiers]
    A --> E[Insufficient Access Control Logic]
    A --> F[Improper Session Handling]
    A --> G[Reliance on Obfuscation]

    B --> H[Horizontal Access Control Failures]
    C --> H
    D --> I[Vertical Access Control Failures]
    E --> I
    F --> J[Context-Dependent Access Control Failures]
    G --> J

Insecure Direct Object References (IDOR) occur when an application exposes a reference to an internal implementation object without sufficient access control. These vulnerabilities allow attackers to manipulate these references to access unauthorized data or perform unauthorized actions.

IDOR vulnerabilities arise from flawed access control mechanisms that fail to validate whether a user should have permission to access or modify a specific resource. The core implementation issues include:

  • Missing Authorization Checks: No validation of user permissions when accessing objects
  • Client-Side ID Transmission: Relying on client-provided identifiers without server-side verification
  • Predictable Resource Identifiers: Sequential or easily guessable object references
  • Insufficient Access Control Logic: Authentication without proper authorization
  • Improper Session Handling: Not binding resources to user sessions
  • Reliance on Obfuscation: Using complex identifiers without actual access control

IDORs manifest in various patterns:

  • Horizontal Access Control Failures: Accessing resources belonging to other users of the same privilege level
  • Vertical Access Control Failures: Accessing resources requiring higher privileges
  • Context-Dependent Access Control Failures: Access based on improper contextual states

Hunt

Identifying IDOR Vulnerabilities

Preparation

  1. Create Multiple Test Accounts:
  • Set up accounts with different privilege levels (e.g., regular user, premium user)
  • Create multiple accounts within the same privilege level
  1. Establish Baseline Behavior:
  • Document normal resource access patterns
  • Map all application endpoints that reference objects
  • Identify resource identifiers in requests
  • Evaluate caching headers (ETag/Last-Modified) that can leak existence side‑channels during enumeration
  1. Request Capture Setup:
  • Configure a proxy (e.g., Burp Suite, OWASP ZAP)
  • For mobile applications, install the proxy’s CA certificate on the device or emulator (e.g., with mitmproxy or Burp Mobile Assistant) so HTTPS traffic can be intercepted.
  • Record all interactions with resource identifiers
  • Create an inventory of potential IDOR test targets

Finding IDOR Vulnerabilities

  1. Request Parameter Analysis:
  • Look for identifiers in URLs, request bodies, cookies, and headers
  • Common parameter names:
id, user_id, account_id, file, doc, document, record, item, order, number, profile,
     edit, view, filename, object, num, key, userid, uuid, group, role
  • Watch for identifiers hidden in JWT claims (sub, org_id) or signed cookies; tamper if server fails to re‑authorize.
  1. Parameter Manipulation Techniques:
  • Direct Modification: Change numerical IDs (e.g., id=1 → id=2)
  • Add Missing IDs: Try adding relevant IDs (e.g., userid, accountid) to requests that don't initially have them (e.g., GET /api/messages → GET /api/messages?user_id=). Parameter names can often be inferred from other requests or discovered using tools like Arjun.
  • GUID/UUID Replacement: Replace one user's GUID with another's
  • Decode and Modify: Decode base64/hex encoded parameters before modification
  • Array/Object Manipulation: Add or modify array elements in API requests
{"items": [{"id": 123, "owner": "victim"}]} → {"items": [{"id": 456, "owner": "attacker"}]}
  • File Type Manipulation: Try changing requested file types or appending extensions (e.g., .json, .xml, .config). Ruby applications might respond differently to /resource/123 vs /resource/123.json.
  • Wildcard Testing: Replace IDs with wildcards (e.g., GET /api/users/*). Rare, but worth trying.
  • Array-based Access: Try wrapping IDs in arrays (e.g., {"id":19} → {"id":[19]}).
  • JSON Object Wrapping: Try wrapping the ID in a nested JSON object (e.g., {"id":111} → {"id":{"id":111}}).
  • Numeric vs Non-Numeric IDs: If the application uses non-numeric IDs (GUIDs, usernames), try substituting them with potential numeric equivalents (e.g., accountid=UUID → accountid=123).
  • Parameter Name Replacement: Try alternative parameter names (e.g., albumid → accountid). Fuzz JSON Patch (RFC 6902) and JSON Merge Patch (RFC 7386) bodies for cross‑user modifications.
  • Multiple Value Testing: Supply multiple values for same parameter (e.g., id=123&id=456, userid=attackerid&userid=victimid, userid=attackerid[]&userid=victimid[]). See HTTP Parameter Pollution under Bypass Techniques.
  • New Feature Focus: Pay special attention to newly added features as they may have weaker access controls; include mobile and older API versions.
  • Cache Probing: Use CDN cache keys and If-None-Match probing to infer existence without full access.

For each endpoint receiving an object ID, ask:

  1. Endpoint Analysis Questions:
  • Does this ID reference a private or sensitive resource (vs. public)?
  • What are my legitimate IDs for this type of resource?
  • What are the different user roles interacting with this API? (user, admin, manager, etc.)
  1. Hidden Parameter Discovery:
  • Analyze JavaScript client-side code for hidden parameters
  • Check mobile app API communications
  • Examine response data for additional identifiable references
  1. Web Socket Discovery:
  • Identify how websockets are being initiated
  • Check if we can manipulate it to change anything
  • Make sure to test mobile/desktop applications of the target as well
  • Inspect mobile deep links and intent filters that include object IDs; try cross‑app invocation.
  1. Testing Methodology:
  2. Access resource as User A and capture the request
  3. Note all identifiers (explicit and obfuscated)
  4. Log in as User B
  5. Replay User A's request with User B's session
  6. Modify identifiers to access resources belonging to other users
  7. Test both read and write operations(and all other application boundaries)
  8. if there are mobile applications create a unique user for that platform as well and test IDOR

Advanced IDOR Testing Techniques

mindmap
  root((IDOR Testing))
    ::icon(fa fa-bug)
    style root fill:#f96,stroke:#333,stroke-width:2px

    id1(Blind Detection)
      ::icon(fa fa-eye-slash)
      style id1 fill:#bbf,stroke:#33f,stroke-width:1px
      id1.1[Comparative Response Analysis]
        style id1.1 fill:#ddf,stroke:#33f
      id1.2[Out-of-Band Detection]
        style id1.2 fill:#ddf,stroke:#33f
      id1.3[Side-Channel Analysis]
        style id1.3 fill:#ddf,stroke:#33f

    id2(Mass Testing)
      ::icon(fa fa-rocket)
      style id2 fill:#fbf,stroke:#939,stroke-width:1px
      id2.1[Automated Identifier Enumeration]
        style id2.1 fill:#fdf,stroke:#939
      id2.2[Parallel Testing with Burp]
        style id2.2 fill:#fdf,stroke:#939
      id2.3[Pattern Recognition]
        style id2.3 fill:#fdf,stroke:#939

    id3(Protection Bypass)
      ::icon(fa fa-shield)
      style id3 fill:#bfb,stroke:#393,stroke-width:1px
      id3.1[ID Obfuscation Bypass]
        style id3.1 fill:#dfd,stroke:#393
      id3.2[Access Control Bypass]
        style id3.2 fill:#dfd,stroke:#393
      id3.3[Reference Leakage Exploitation]
        style id3.3 fill:#dfd,stroke:#393

Blind IDOR Detection

  1. Comparative Response Analysis:
  • Compare responses between valid and invalid resource IDs
  • Look for subtle differences in response times, sizes, or error messages
  • Use automated tools to detect variations across multiple requests
  1. Out-of-Band Detection:
  • Inject tracking URLs in modifiable parameters
  • Monitor for callbacks when the resource is accessed
  • Use server callbacks to detect successful access
  1. Side-Channel Analysis:
  • Analyze network traffic for additional clues
  • Look for timing differences or response size variations

Mass IDOR Testing

  1. Automated Identifier Enumeration:

More skills from SnailSploit/Claude-Red

  • Aoffensive-active-directoryActive Directory attack methodology for internal network red team engagements. Covers reconnaissance (BloodHound, PowerView, ADExplorer), credential abuse (Kerberoasting, ASREProasting, NTLM relay, LLMNR/NBT-NS poisoning), privilege escalation (ACL abuse, GPO abuse, unconstrained/constrained delegation), lateral movement (Pass-the-Hash, Pass-the-Ticket, Overpass-the-Hash, WMI/WinRM/PsExec), persistence (Golden/Silver/Diamond Tickets, DCSync, DCShadow, AdminSDHolder, Skeleton Key), forest trust attacks, ADCS abuse (ESC1-ESC15), and modern MDI/Defender for Identity evasion. Use when assessing on-prem AD, hybrid AD/Entra ID environments, or ADCS deployments.
  • Aoffensive-advanced-redteamComprehensive red team operations methodology covering full engagement lifecycle from planning through reporting. Addresses engagement scoping and rules of engagement negotiation, multi-tier C2 infrastructure design with redirectors and domain fronting, malleable traffic profiles and beacon tradecraft, OPSEC discipline including attribution avoidance and indicator management, EDR and AMSI evasion techniques using direct syscalls and unhooking, data collection with chain-of-custody controls, and structured reporting with purple team debrief workflows. Covers assumed-breach, external-to-internal, insider threat, and hybrid physical-cyber engagement scenarios with MITRE ATT&CK mapping throughout. Targets operators planning or executing adversary simulation engagements against mature defenders.
  • Coffensive-ai-security
  • Aoffensive-anti-forensicsAnti-forensics and evidence destruction techniques for red team operators conducting authorized engagements. Covers log clearing on Windows (wevtutil, Clear-EventLog, ETW provider patching) and Linux (journal truncation, utmp/wtmp binary editing, syslog manipulation), timestamp manipulation via Timestomp and SetMACE to defeat timeline analysis, filesystem-level anti-forensics including NTFS Alternate Data Streams for payload hiding and secure deletion with sdelete/shred, memory artifact removal to counter live forensics, disk artifact manipulation targeting MFT entries and USN journal records, network forensics evasion through encrypted C2 channels and DNS-over-HTTPS tunneling, and anti-VM/sandbox detection to avoid dynamic analysis environments. Tools: Timestomp, wevtutil, sdelete, shred, MimiPenguin, Invoke-Phant0m. Aligns to MITRE ATT&CK T1070 (Indicator Removal), T1027 (Obfuscated Files or Information), T1497 (Virtualization/Sandbox Evasion). Each technique includes the forensic artifact it targets, the destruction or manipulation method, and the defender perspective so operators understand detection gaps they must account for.
  • Aoffensive-api-abuseAdvanced API exploitation methodology focused on business logic abuse and sophisticated attack patterns that bypass traditional security controls. Covers business logic bypass through API call chaining and workflow manipulation. Addresses GraphQL-specific attacks including batching for credential brute-force, query depth exploitation, and introspection abuse. Includes pagination exploitation for data exfiltration, webhook hijacking for SSRF and data interception, and resource exhaustion through algorithmic complexity attacks. Covers race conditions in API transactions using parallel request techniques. Provides comprehensive JWT manipulation including algorithm confusion, kid injection, jku/x5u abuse, and claim tampering. Details API key leakage detection across source repositories, client-side code, and error messages. Covers undocumented endpoint discovery through predictable naming, debug routes, and source map analysis. Tooling includes Arjun, ParamSpider, jwt_tool, and GraphQL Voyager. Designed for authorized penetration testers targeting business logic layers that automated scanners miss.
  • Aoffensive-api-securityComprehensive API security testing methodology covering REST, gRPC, and WebSocket attack surfaces. Addresses the full OWASP API Security Top 10 2023 including BOLA/IDOR, broken authentication, excessive data exposure, rate limiting bypass, BFLA, mass assignment, SSRF, and security misconfiguration. Includes REST-specific attacks such as HTTP verb tampering, content-type switching, and parameter pollution. Covers gRPC exploitation through protobuf interception, reflection API enumeration, and metadata injection. Addresses WebSocket vulnerabilities including origin bypass, message injection, and cross-site WebSocket hijacking. Provides tooling guidance for Burp Suite, Postman, grpcurl, websocat, and mitmproxy. Each technique includes detection signatures and defensive indicators so you understand what artifacts your testing leaves behind. Designed for authorized penetration testing engagements against API-driven architectures.
  • Aoffensive-bluetooth-bleBluetooth Low Energy (BLE) attack methodology — GATT enumeration, characteristic read/write without auth, pairing downgrade (Just Works forced), LE Secure Connections bypass, MITM via active relay, sniffing with Sniffle (TI CC1352) / Ubertooth / Frontline, encryption key extraction (LE Legacy Pairing crackable, LE Secure Connections strong), proximity authentication abuse (cars, locks), and companion-app trust analysis. Use for IoT BLE devices, smart locks, fitness trackers, medical devices, BLE beacons, or any device pairing over BLE.
  • Aoffensive-bluetooth-classicBluetooth Classic (BR/EDR) attack methodology — device discovery, service enumeration via SDP, LMP/L2CAP layer attacks, legacy PIN cracking (BlueBorne / KNOB), Bluetooth file-transfer abuse (BlueSnarfing legacy), unauthenticated profile abuse (HSP, HFP, OPP), and modern relevance against older industrial / automotive / accessory targets. Use when in-scope devices use Bluetooth Classic (Bluetooth ≤ 4.0 BR/EDR) — common in legacy car kits, industrial sensors, older medical devices, and audio accessories.
  • Aoffensive-bug-identification
  • Aoffensive-business-logicBusiness logic vulnerability testing for web/mobile/API engagements. Covers workflow bypass, state machine violations, multi-step process abuse, price/quantity/discount manipulation, currency confusion, coupon stacking, refund/chargeback abuse, race conditions on logic boundaries, parameter tampering for hidden flows, role/tenant boundary violations, time-of-check vs use, anti-automation defeat, fraud-detection evasion, and subscription/quota abuse. Use when scoping an application after surface-level OWASP Top 10 has been covered, or when the asset is a transactional/marketplace/fintech/e-commerce/SaaS app where logic flaws produce direct financial impact.
  • Aoffensive-c2-frameworksCommand and Control framework deployment, configuration, and operational tradecraft for red team engagements. Covers Cobalt Strike (malleable C2 profiles, Beacon types HTTP/HTTPS/DNS/SMB, Beacon Object Files for in-memory execution, sleep and jitter tuning, named pipe pivoting), Sliver (implant generation across mTLS/WireGuard/DNS transport, operator multiplayer mode, armory extensions), Mythic (agent ecosystem with Apollo/Poseidon/Medusa, C2 profile configuration, translation containers), Havoc (Demon agent with sleep obfuscation via Ekko/Zilean, indirect syscalls, dotnet inline execution), Metasploit (msfvenom payload generation, multi/handler staging, Meterpreter post-exploitation modules), redirector architecture using Apache mod_rewrite and Nginx, domain fronting through CDN providers, DNS-based C2 for restrictive network egress, and TLS certificate management for infrastructure OPSEC. Tools: Cobalt Strike, Sliver, Mythic, Havoc, Metasploit Framework. Aligns to MITRE ATT&CK T1071 (Application Layer Protocol), T1573 (Encrypted Channel), T1090 (Proxy/Connection Proxy).
  • Doffensive-cicd-pipelineComprehensive CI/CD pipeline exploitation methodology covering GitHub Actions injection vectors (expression injection via PR titles and issue bodies, workflow_run event abuse, GITHUB_TOKEN over-scoping, composite action supply chain compromise), Jenkins attack paths (Groovy sandbox escapes, script console remote code execution, Java remoting deserialization, credential store dumping, shared library injection), GitLab CI exploitation (YAML anchor injection, runner registration token abuse, CI variable extraction, protected branch bypass via merge request pipelines), and Azure DevOps pipeline agent compromise with service connection theft. Includes artifact poisoning techniques across all platforms, tooling guidance for gato and jenkins-attack-framework, and maps to MITRE ATT&CK T1195.002 (Supply Chain Compromise: Compromise Software Supply Chain). Covers enumeration of pipeline configurations, privilege escalation from contributor to code execution, lateral movement through pipeline trust boundaries, and persistence via modified workflow definitions. Each technique section provides working exploitation code, detection indicators, and defensive countermeasures.

All agent skills → · MCP servers