How I Found IDORs That Shouldn’t Exist @AmrSecOfficial
How I Found IDORs That Shouldn’t Exist  @AmrSecOfficial
Uploaded October 2025 | Updated September 2026, 6 hours ago
In this episode, we’re diving straight into one of the most overlooked - and most powerful vulnerabilities in bug bounty: IDORs and broken access controls.
No definitions, no theory - just the real mindset, the logic, and the techniques that turn a simple β€œ403 Forbidden” into full access.

🎯 Get My Full Caido For Hackers Course: hhub.io/AMRCAIDO

πŸ’‘ Support AmrSec on Patreon:
patreon.com/AmrSec

πŸ”₯ Join Our Community:
Discord: discord.gg/nxHKyJTy3h

πŸ“‘ Resources
Video Article: amrelsagaei.com/how-i-found-idors-that-shouldnt-exist
YWH: yeswehack.com
YWH DoJo: dojo-yeswehack.com

⭐ Become a Channel Member:
youtube.com/@AmrSecOfficial/join

🟠 Get 20% off Caido Premium with code "AMRSEC20" (yearly plan only)

⚠️ Disclaimer
This channel is for educational purposes only. The goal is to teach cybersecurity, ethical hacking, and red team/blue team skills through real tools, techniques, and experience. Always hack ethically. πŸ”

⏱️ Timestamps
00:00 β€” Introduction
00:44 β€” Quick Note
01:17 β€” IDOR Reality
01:49 β€” How to Think (Mindset Shift)
02:30 β€” Techniques Overview
05:18 β€” Trailing Slash / Path Normalization
06:08 β€” Double-Slash / Obfuscated Path
06:50 β€” Version Downgrade
07:36 β€” Subpath / Endpoint Variant
09:01 β€” Query Param vs Path
11:07 β€” Type Confusion β€” String vs Integer
11:58 β€” Leading Zeros / Hex / Alternate Formats
12:26 β€” NULL / Termination / Control-Char Encoding
13:17 β€” Header / Proxy-Based Bypass
14:13 β€” Unicode / Encoded-Space Tricks
17:08 β€” Quick Recap
17:49 β€” Conclusion

Follow AmrSec
LinkedIn: linkedin.com/in/amrelsagaei
Twitter/X: twitter.com/amrelsagaei
Instagram: instagram.com/amrelsagaei

#AmrSec #BugBounty #IDOR #WebSecurity #CyberSecurity #YesWeHack
How I Found IDORs That Shouldn’t ExistClient Side 02: ServiceWorker BugsOpenSource Code Analysis With AI!what exactly is a template engine and how it works?API Penetration Testing πŸ” Part 2
AmrSec |

How I Found IDORs That Shouldn’t Exist

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER