Mass Assignment
By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security
Automatically unpacking data from the HTTP request can sometimes be too easy.
- Prevalence
- Occasional
- Exploitability
- Easy
- Impact
- Harmful
What is mass assignment?
Mass assignment is a parameter tampering attack that targets frameworks which automatically copy HTTP request parameters onto the fields of an object. An attacker adds parameters the form never offered, such as is_admin=true, and the framework writes them to the database. It lets attackers change fields such as roles, balances or ownership that should be read-only.
What you'll learn
- How frameworks that bind request parameters to objects can be abused
- How one extra field in a forged request changes a protected property
- How to enumerate the properties a request is allowed to update
Where this lesson counts
OWASP Top 10
Code and data are trusted without verifying integrity, from unsafe deserialization to unchecked object updates.
Binding request parameters straight onto objects is an integrity failure: the client dictates fields it should never touch.
Learn more about A08This lesson includes
-
Mass Assignment lab
A profile page lets users update their email and password, and the server copies every field in the request onto the User object. See how an attacker forges a request with one extra field and makes themselves an administrator, no admin button required.
-
How to prevent Mass Assignment
The prevention guide covers two approaches:
- Explicitly Enumerate the Properties You Update
- Never Bind Sensitive Fields from the Request
-
Mass Assignment quiz
Two questions. Passing marks the lesson complete.
Sources
- What is Mass Assignment? Attacks and Security Tips Vaadata
- CWE-915 MITRE
- Mass Assignment Secure Code Warrior
- Mass Assignment in Ruby on Rails Rails Guides
Related lessons
Browse all 45 lessons
Privilege Escalation
Privilege escalation occurs when an attacker exploits a vulnerability to impersonate another user or gain extra permissions.
Broken Access Control
All resources on your site need to have access control implemented, even if they aren't intended to be discoverable by a user.
Prototype Pollution
If an attacker can access and modify prototype objects in JavaScript, you are in danger.
Insecure Design
Security begins before you start writing code.