{"id":66,"date":"2026-05-26T06:08:29","date_gmt":"2026-05-26T06:08:29","guid":{"rendered":"https:\/\/alwaysbenoobing.com\/?p=66"},"modified":"2026-05-27T12:54:35","modified_gmt":"2026-05-27T12:54:35","slug":"66","status":"publish","type":"post","link":"https:\/\/alwaysbenoobing.com\/index.php\/2026\/05\/26\/66\/","title":{"rendered":"LetsDefend IDOR Attack Detected Walkthrough"},"content":{"rendered":"\n<h1 class=\"wp-block-heading\">119 &#8211; SOC169 Exercise on LetsDefend<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">IDOR attacks happen when an application directly uses a user supplied input to access data. &nbsp;Without authorization, that same parameter can be manipulated to access data that should not be available to the current user. &nbsp;IDOR is synonymous with BOLA or Broken Object Level Authorization.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If a user is logged into a web app and the URL is displayed as:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>https:&#47;&#47;example.com\/profile?user_id=12345<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">If proper authorization is not checked, a user may be able to change the user_id parameter to an arbitrary value. This may be another user (user_id=12344), or possibly admin (user_id=1)?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These Direct Object References can refer to any object within the web app such as users, order identifiers, document numbers, etc., and without proper authorization, can give access to unintended users. &nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This vulnerability is dangerous because it can lead to mass data exposure, account takeover, or full compromise of the server. &nbsp;It is also easily automated with a tool like Burp or handwritten scripts.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The following is a walk-through for detecting an IDOR attack from the letsdefend.io platform.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Alert Ownership and Case Creation<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">In the <strong>MAIN CHANNEL<\/strong> tab of the practice SIEM you will first assign the alert to yourself by clicking the \u2018Take Ownership\u2019 Action button.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"102\" src=\"https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/Possible-IDOR-Attack-Detected-1024x102.jpg\" alt=\"\" class=\"wp-image-78\" srcset=\"https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/Possible-IDOR-Attack-Detected-1024x102.jpg 1024w, https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/Possible-IDOR-Attack-Detected-300x30.jpg 300w, https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/Possible-IDOR-Attack-Detected-768x76.jpg 768w, https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/Possible-IDOR-Attack-Detected-1536x152.jpg 1536w, https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/Possible-IDOR-Attack-Detected.jpg 1623w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Next, move to the <strong>INVESTIGATION CHANNEL<\/strong> tab and expand the alert and gather information.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"443\" src=\"https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/1_Possible-IDOR-Attack-Detected-1024x443.jpg\" alt=\"\" class=\"wp-image-68\" srcset=\"https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/1_Possible-IDOR-Attack-Detected-1024x443.jpg 1024w, https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/1_Possible-IDOR-Attack-Detected-300x130.jpg 300w, https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/1_Possible-IDOR-Attack-Detected-768x332.jpg 768w, https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/1_Possible-IDOR-Attack-Detected-1536x664.jpg 1536w, https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/1_Possible-IDOR-Attack-Detected.jpg 1625w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Here we see info such as the Date &amp; Time, Hostname, Destination IP, Source IP, and the URL requested.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Click the \u201cCreate Case\u201d Action to begin working on the case.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Playbook<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Clicking \u201cStart Playbook\u201d details what information the SOC Analyst should be investigating and this is where you will answer questions and write case notes to close the investigation. &nbsp;You can close this and come back to answer questions after your investigation.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"634\" height=\"400\" src=\"https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/5_Possible-IDOR-Attack-Detected.jpg\" alt=\"\" class=\"wp-image-72\" srcset=\"https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/5_Possible-IDOR-Attack-Detected.jpg 634w, https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/5_Possible-IDOR-Attack-Detected-300x189.jpg 300w\" sizes=\"auto, (max-width: 634px) 100vw, 634px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">IP Ownership<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">AbuseIPDB can be used to query IP addresses to find reputational data. &nbsp;Querying the source IP address reveals an IP address from DigitalOcean, LLC that has been reported in multiple malicious events. &nbsp;<a href=\"https:\/\/www.abuseipdb.com\">https:\/\/www.abuseipdb.com<\/a>&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"631\" height=\"402\" src=\"https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/6_Possible-IDOR-Attack-Detected.jpg\" alt=\"\" class=\"wp-image-73\" srcset=\"https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/6_Possible-IDOR-Attack-Detected.jpg 631w, https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/6_Possible-IDOR-Attack-Detected-300x191.jpg 300w\" sizes=\"auto, (max-width: 631px) 100vw, 631px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Cisco Talos rates the Sender IP Reputation as Poor.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"251\" src=\"https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/7_Possible-IDOR-Attack-Detected-1024x251.jpg\" alt=\"\" class=\"wp-image-74\" srcset=\"https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/7_Possible-IDOR-Attack-Detected-1024x251.jpg 1024w, https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/7_Possible-IDOR-Attack-Detected-300x73.jpg 300w, https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/7_Possible-IDOR-Attack-Detected-768x188.jpg 768w, https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/7_Possible-IDOR-Attack-Detected.jpg 1234w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">This is an external IP address with a Poor reputation. &nbsp;Traffic is coming from the Internet from an address pool.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Log Investigation<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Let&#8217;s look at the logs generated that fired this alert to validate it. Go to <strong>Log Management<\/strong> and click the search bar to filter for logs with the destination of the attacked machine. &#8220;Destination Address equals 172.16.17.15&#8221;&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There are 5 events listed all coming from the same source_address IP. &nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"357\" src=\"https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/2_Possible-IDOR-Attack-Detected-1024x357.jpg\" alt=\"\" class=\"wp-image-69\" srcset=\"https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/2_Possible-IDOR-Attack-Detected-1024x357.jpg 1024w, https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/2_Possible-IDOR-Attack-Detected-300x104.jpg 300w, https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/2_Possible-IDOR-Attack-Detected-768x267.jpg 768w, https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/2_Possible-IDOR-Attack-Detected-1536x535.jpg 1536w, https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/2_Possible-IDOR-Attack-Detected.jpg 1588w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">When the log is expanded, we see the source IP, destination IP, and the URL request and the POST parameters supplied in the URL. &nbsp;The HTTP Response Status and HTTP Response Size are also important here. &nbsp;A Response Status of 4XX or 5XX indicates an unsuccessful attempt and the requested data was not returned to the user\/attacker. &nbsp;Status 200 messages indicate a successful request, 3XX may be successfully redirected requests.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"663\" height=\"269\" src=\"https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/3_Possible-IDOR-Attack-Detected.jpg\" alt=\"\" class=\"wp-image-70\" srcset=\"https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/3_Possible-IDOR-Attack-Detected.jpg 663w, https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/3_Possible-IDOR-Attack-Detected-300x122.jpg 300w\" sizes=\"auto, (max-width: 663px) 100vw, 663px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Just because the request was successful does not mean that information was leaked. &nbsp;You must also look at the HTTP Response Size. &nbsp;If the Response Status were all 200 OK messages, but the response sizes are all identical, it is more likely that all requests have successfully reached an \u201cInvalid Request\u201d page. &nbsp;If the Response Sizes are unique, the data returned from the request are unique, which indicates a successful leak of information.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"641\" height=\"267\" src=\"https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/4_Possible-IDOR-Attack-Detected.jpg\" alt=\"\" class=\"wp-image-71\" srcset=\"https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/4_Possible-IDOR-Attack-Detected.jpg 641w, https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/4_Possible-IDOR-Attack-Detected-300x125.jpg 300w\" sizes=\"auto, (max-width: 641px) 100vw, 641px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">All 5 log entries have HTTP Response Status 200, as well as unique HTTP Response Sizes indicating a successful attack has been performed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If we filter the logs for the source_ip of the attacking machine, we see that there are only the same 5 entries, so no additional machines have been attacked by this IP address.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Email Security<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Searching hostname, username, and IP address does not reveal anything about having a planned security test scheduled at this time.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Endpoint Containment<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Go to Endpoint Security and search for the WebServer1005 machine. &nbsp;Since the machine is known to be compromised, request host containment to limit additional compromise.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"262\" src=\"https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/8_Possible-IDOR-Attack-Detected-1024x262.jpg\" alt=\"\" class=\"wp-image-75\" srcset=\"https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/8_Possible-IDOR-Attack-Detected-1024x262.jpg 1024w, https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/8_Possible-IDOR-Attack-Detected-300x77.jpg 300w, https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/8_Possible-IDOR-Attack-Detected-768x196.jpg 768w, https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/8_Possible-IDOR-Attack-Detected-1536x393.jpg 1536w, https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/8_Possible-IDOR-Attack-Detected.jpg 1662w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Answering Playbook<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The traffic is malicious, it is confirmed to have successfully performed and IDOR attack.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Type of Attack is IDOR.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is NOT a Planned Test.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Traffic is from Internet \u2192 Company Network<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We verified that the attack was indeed Successful.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Add Artifacts the the case (Source IP, Destination IP, URL request):<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"798\" height=\"452\" src=\"https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/9_Possible-IDOR-Attack-Detected.jpg\" alt=\"\" class=\"wp-image-76\" srcset=\"https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/9_Possible-IDOR-Attack-Detected.jpg 798w, https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/9_Possible-IDOR-Attack-Detected-300x170.jpg 300w, https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/9_Possible-IDOR-Attack-Detected-768x435.jpg 768w\" sizes=\"auto, (max-width: 798px) 100vw, 798px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Since the attack was successful, escalate the case to Tier 2 support.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Analyst Note<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>An alert for a possible IDOR attack was triggered for WebServer1005 at IP address 172.16.17.15.  A successful IDOR attack was confirmed via webserver logs to the URL https:\/\/172.16.17.15\/get_user_info\/ by supplying arbitrary user_id parameters.   Request Response was 200 with unique Response Size.\nThe attacker is external from a DigitalOcean address with poor reputation.  134.209.118.137.  \nThe machine was isolated and escalated to Tier 2.<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Click Finish Playbook to finish the analysis.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Close the alert to finish the investigation.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"98\" src=\"https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/10_Possible-IDOR-Attack-Detected-1024x98.jpg\" alt=\"\" class=\"wp-image-77\" srcset=\"https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/10_Possible-IDOR-Attack-Detected-1024x98.jpg 1024w, https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/10_Possible-IDOR-Attack-Detected-300x29.jpg 300w, https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/10_Possible-IDOR-Attack-Detected-768x74.jpg 768w, https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/10_Possible-IDOR-Attack-Detected-1536x148.jpg 1536w, https:\/\/alwaysbenoobing.com\/wp-content\/uploads\/2026\/05\/10_Possible-IDOR-Attack-Detected.jpg 1622w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Write an Analyst note and close the investigation:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>On the Log Management page, we filter by source IP address and detect all requests.\nWhen the requests were examined, it was determined that the attacker wanted to change the ID value and access information belonging to different users.\nWhen the request sizes are examined, there is a different response size for each user and the status code is 200. For this reason, the attack is considered to have been successful.\nSince the attack may have been successful, the device should be contained and escalated to Tier 2.<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Clicking on the Results will reveal how you have been scored according how you answered the Playbook. &nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I&#8217;ve been using LetsDefend for about a week now, and feel like it is exactly what I have been missing in my education. &nbsp;I have completed a B.S. Cyber Security \/ Information Assurance from WGU and did not feel comfortable that my skills were directly applicable to a SOC Analyst role as far as day-to-day tasks. &nbsp;Practicing with LetsDefend&#8217;s SIEM alerts has provided me the hands-on practice that I was looking for.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>119 &#8211; SOC169 Exercise on LetsDefend IDOR attacks happen when an application directly uses a user supplied input to access data. &nbsp;Without authorization, that same parameter can be manipulated to access data that should not be available to the current user. &nbsp;IDOR is synonymous with BOLA or Broken Object Level Authorization. If a user is [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-66","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/alwaysbenoobing.com\/index.php\/wp-json\/wp\/v2\/posts\/66","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/alwaysbenoobing.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/alwaysbenoobing.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/alwaysbenoobing.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/alwaysbenoobing.com\/index.php\/wp-json\/wp\/v2\/comments?post=66"}],"version-history":[{"count":6,"href":"https:\/\/alwaysbenoobing.com\/index.php\/wp-json\/wp\/v2\/posts\/66\/revisions"}],"predecessor-version":[{"id":85,"href":"https:\/\/alwaysbenoobing.com\/index.php\/wp-json\/wp\/v2\/posts\/66\/revisions\/85"}],"wp:attachment":[{"href":"https:\/\/alwaysbenoobing.com\/index.php\/wp-json\/wp\/v2\/media?parent=66"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/alwaysbenoobing.com\/index.php\/wp-json\/wp\/v2\/categories?post=66"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/alwaysbenoobing.com\/index.php\/wp-json\/wp\/v2\/tags?post=66"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}