Web Application Authorization: Taming the Perfect Storm | Tim Tomes @WildWestHackinFest
Web Application Authorization: Taming the Perfect Storm | Tim Tomes  @WildWestHackinFest
Uploaded January 2026 | Updated September 2026, 2 weeks ago
Web Application Authorization: Taming the Perfect Storm
Presenter: Tim Tomes

Access control vulnerabilities are everywhere. Across my last 40 web application security assessments, I identified 41 access control related findings, which means almost every modern application has at least one serious flaw. This aligns with OWASP, which ranks Broken Access Control as the number one risk facing web applications today. But why is this problem so persistent?

The simple answer is that access control is difficult. It is difficult to design, difficult to implement, difficult to maintain, and difficult to test. When these challenges collide, they create the perfect storm for privilege escalation and unintended data exposure. However, those who deeply understand these systems and know how to evaluate them can turn this storm into an advantage.

In this talk, I will help you build that skillset. We will explore the most common pitfalls across different application architectures, and I will walk through the tools and techniques I use to uncover access control flaws in real systems. We will also cover practical remediation approaches and discuss how development teams can automate access control testing within a CI/CD pipeline, which many still believe to be impossible.

Sign Up for WWHF
wildwesthackinfest.com/register

#appsec #websecurity #owasp #brokenaccesscontrol #pentesting #securitytesting #infosec #cybersecurity #wwhf #wwhf2026
///Black Hills Infosec Socials
Twitter: twitter.com/BHinfoSecurity
Mastodon: https://infosec.exchange/@blackhillsinfosec
LinkedIn: linkedin.com/company/antisyphon-training
Discord: discord.gg/ffzdt3WUDe

///Black Hills Infosec Shirts & Hoodies
spearphish-general-store.myshopify.com/collections/bhis-shirt-collections

///Black Hills Infosec Services
Active SOC: blackhillsinfosec.com/services/active-soc
Penetration Testing: blackhillsinfosec.com/services
Incident Response: blackhillsinfosec.com/services/incident-response

///Backdoors & Breaches - Incident Response Card Game
Backdoors & Breaches: backdoorsandbreaches.com
Play B&B Online: play.backdoorsandbreaches.com

///Antisyphon Training
Pay What You Can: antisyphontraining.com/pay-what-you-can
Live Training: antisyphontraining.com/course-catalog
On Demand Training: antisyphontraining.com/on-demand-course-catalog
Antisyphon Discord: discord.gg/antisyphon
Antisyphon Mastodon: https://infosec.exchange/@Antisy_Training

///Educational Infosec Content
Black Hills Infosec Blogs: blackhillsinfosec.com/blog
Wild West Hackin' Fest YouTube: youtube.com/wildwesthackinfest
Antisyphon Training YouTube: youtube.com/antisyphontraining
Active Countermeasures YouTube: youtube.com/activecountermeasures
Threat Hunter Community Discord: discord.gg/threathunter

Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — Wild West Hackin' Fest: wildwesthackinfest.com
Web Application Authorization: Taming the Perfect Storm | Tim TomesWorkshop: Automating Attacks | Alex Martirosyan | WWHF 2023Tool Shed Demo: ELROND | Ben Smith | WWHF 2023Large Language Models: Disinformation and the Future of Work | Heather  Lawrence | WWHF 2023Unintentional Hackers: Students as the Weakest (and Wildest) Link | Jacob ThompsonThe Hackening: Lessons Learned Compromising MSPs! | Matt Lee, Jason SlagleTrust Me, Im a Shortcut: New LNK Abuse Methods | Wietze BeukemaLost Underground | Ray and Mike Felch | WWHF 2023Tow Away Zone –The Dark Side of Domain Parking | Cameron CartierTOOL: DarkWidow | Soumyanil BiswasThe Terminator Effect: AIs Role in Fighting Cyber Threats | James McQuiggan | WWHF 2023Building a Winning Team Culture | Heath Adams | WWHF 2023
Wild West Hackin Fest |

Web Application Authorization: Taming the Perfect Storm | Tim Tomes

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER