20–30 min Updated

Mass Assignment

By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security

Automatically unpacking data from the HTTP request can sometimes be too easy.

Prevalence
Occasional
Exploitability
Easy
Impact
Harmful

What is mass assignment?

Mass assignment is a parameter tampering attack that targets frameworks which automatically copy HTTP request parameters onto the fields of an object. An attacker adds parameters the form never offered, such as is_admin=true, and the framework writes them to the database. It lets attackers change fields such as roles, balances or ownership that should be read-only.

What you'll learn

  • How frameworks that bind request parameters to objects can be abused
  • How one extra field in a forged request changes a protected property
  • How to enumerate the properties a request is allowed to update

Where this lesson counts

OWASP Top 10

  • Mass Assignment lab

    A profile page lets users update their email and password, and the server copies every field in the request onto the User object. See how an attacker forges a request with one extra field and makes themselves an administrator, no admin button required.

  • How to prevent Mass Assignment

    The prevention guide covers two approaches:

    • Explicitly Enumerate the Properties You Update
    • Never Bind Sensitive Fields from the Request
  • Mass Assignment quiz

    Two questions. Passing marks the lesson complete.

Sources

  • Privilege Escalation

    Privilege escalation occurs when an attacker exploits a vulnerability to impersonate another user or gain extra permissions.

  • Broken Access Control

    All resources on your site need to have access control implemented, even if they aren't intended to be discoverable by a user.

  • Prototype Pollution

    If an attacker can access and modify prototype objects in JavaScript, you are in danger.

  • Insecure Design

    Security begins before you start writing code.