15–25 min Updated

Privilege Escalation

By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security

Privilege escalation occurs when an attacker exploits a vulnerability to impersonate another user or gain extra permissions.

Prevalence
Occasional
Exploitability
Moderate
Impact
Devastating

What is privilege escalation?

Privilege escalation is an authorization attack in which an attacker gains permissions they should not have. Vertical escalation grants a higher role, such as administrator, while horizontal escalation grants access to another user's account. It occurs when code makes access decisions using untrusted input, such as a role or user ID sent in the request.

What you'll learn

  • The difference between vertical and horizontal privilege escalation
  • Why cookies and hidden form fields are untrusted input
  • How to keep access decisions on the server and tamper-proof your cookies

Where this lesson counts

OWASP Top 10

PCI DSS 4.0

  • Privilege Escalation lab

    Watch two attackers edit what the browser sends back. Trix changes the user ID in her cookie to impersonate another account, and Slim rewrites a hidden role field in a form to make himself an admin. Both work because the server trusts the values.

  • How to prevent Privilege Escalation

    The prevention guide covers three approaches:

    • Keeping it Server Side
    • Tamper-Proofing Cookies
    • Encrypting Data
  • Privilege Escalation quiz

    Three questions. Passing marks the lesson complete.

  • Broken Access Control

    All resources on your site need to have access control implemented, even if they aren't intended to be discoverable by a user.

  • Mass Assignment

    Automatically unpacking data from the HTTP request can sometimes be too easy.

  • Directory Traversal

    Ensure file paths are safely interpreted, or hackers can access sensitive files on your server.

  • User Enumeration

    Leaking username information on your site makes things much easier for hackers.