Skip to content
Vulnerability field guide

Access Control

A 403 Forbidden only proves that one spelling of a request was refused. Here is how trailing slashes, path parameters, rewrite headers like X-Original-URL, spoofed client IPs and alternate methods walk past gates enforced at a proxy or router, and why the decision has to live in the application.

1 article 8 min total Overview to advanced techniques