Privilege Escalation
By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security
Privilege escalation occurs when an attacker exploits a vulnerability to impersonate another user or gain extra permissions.
- Prevalence
- Occasional
- Exploitability
- Moderate
- Impact
- Devastating
What is privilege escalation?
Privilege escalation is an authorization attack in which an attacker gains permissions they should not have. Vertical escalation grants a higher role, such as administrator, while horizontal escalation grants access to another user's account. It occurs when code makes access decisions using untrusted input, such as a role or user ID sent in the request.
What you'll learn
- The difference between vertical and horizontal privilege escalation
- Why cookies and hidden form fields are untrusted input
- How to keep access decisions on the server and tamper-proof your cookies
Where this lesson counts
OWASP Top 10
Users act outside their intended permissions, exposing or modifying data they should never reach. Now includes SSRF.
Learn more about A01PCI DSS 4.0
Requirement 6.2.4: engineering techniques must prevent injection, data-structure, cryptographic, business-logic and access-control attacks in bespoke software.
Learn more about 6.2.4Requirement 7.2.1: access to system components and data must follow a defined model based on business need and least privilege.
Learn more about 7.2.1This lesson includes
-
Privilege Escalation lab
Watch two attackers edit what the browser sends back. Trix changes the user ID in her cookie to impersonate another account, and Slim rewrites a hidden role field in a form to make himself an admin. Both work because the server trusts the values.
-
How to prevent Privilege Escalation
The prevention guide covers three approaches:
- Keeping it Server Side
- Tamper-Proofing Cookies
- Encrypting Data
-
Privilege Escalation quiz
Three questions. Passing marks the lesson complete.
Related lessons
Browse all 45 lessons
Broken Access Control
All resources on your site need to have access control implemented, even if they aren't intended to be discoverable by a user.
Mass Assignment
Automatically unpacking data from the HTTP request can sometimes be too easy.
Directory Traversal
Ensure file paths are safely interpreted, or hackers can access sensitive files on your server.
User Enumeration
Leaking username information on your site makes things much easier for hackers.