<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Broken Access Control :: soapsec</title>
    <link>/web-attacks/broken-access-control/index.html</link>
    <description></description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Sun, 19 Jul 2026 14:14:10 +0100</lastBuildDate>
    <atom:link href="/web-attacks/broken-access-control/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Why are These Vulnerabilities So Prevalent? A01 Broken Access Control</title>
      <link>/web-attacks/broken-access-control/bac/index.html</link>
      <pubDate>Sun, 19 Jul 2026 14:14:10 +0100</pubDate>
      <guid>/web-attacks/broken-access-control/bac/index.html</guid>
      <description>Intro In my last blog post, I walked through a blind out-of-band SQL Injection vulnerability I discovered during a web application pentest and the complexities / difficulties I faced during that engagement. This blog post will be a little different. Instead of an engagement story, we’re going to look at Broken Access Control, the category that sits at #1 on the OWASP Top 10 and one of the most commonly found issues in web apps.</description>
    </item>
  </channel>
</rss>