关于
This skill provides a comprehensive security testing framework designed to identify broken access control issues where unauthorized users might access or modify private data. It offers detailed methodologies for testing database object references, static file exposures, and API endpoints using techniques like parameter manipulation and automated enumeration. Whether you are performing a penetration test or securing your own codebase, this skill delivers step-by-step instructions for using tools like Burp Suite and provides actionable remediation code to implement robust server-side authorization checks.