Uploaded January 2026 | Updated September 2026, 2 weeks ago
Web Application Authorization: Taming the Perfect Storm
Presenter: Tim Tomes
Access control vulnerabilities are everywhere. Across my last 40 web application security assessments, I identified 41 access control related findings, which means almost every modern application has at least one serious flaw. This aligns with OWASP, which ranks Broken Access Control as the number one risk facing web applications today. But why is this problem so persistent?
The simple answer is that access control is difficult. It is difficult to design, difficult to implement, difficult to maintain, and difficult to test. When these challenges collide, they create the perfect storm for privilege escalation and unintended data exposure. However, those who deeply understand these systems and know how to evaluate them can turn this storm into an advantage.
In this talk, I will help you build that skillset. We will explore the most common pitfalls across different application architectures, and I will walk through the tools and techniques I use to uncover access control flaws in real systems. We will also cover practical remediation approaches and discuss how development teams can automate access control testing within a CI/CD pipeline, which many still believe to be impossible.
Sign Up for WWHF
wildwesthackinfest.com/register
#appsec #websecurity #owasp #brokenaccesscontrol #pentesting #securitytesting #infosec #cybersecurity #wwhf #wwhf2026
///Black Hills Infosec Socials
Twitter: twitter.com/BHinfoSecurity
Mastodon: https://infosec.exchange/@blackhillsinfosec
LinkedIn: linkedin.com/company/antisyphon-training
Discord: discord.gg/ffzdt3WUDe
///Black Hills Infosec Shirts & Hoodies
spearphish-general-store.myshopify.com/collections/bhis-shirt-collections
///Black Hills Infosec Services
Active SOC: blackhillsinfosec.com/services/active-soc
Penetration Testing: blackhillsinfosec.com/services
Incident Response: blackhillsinfosec.com/services/incident-response
///Backdoors & Breaches - Incident Response Card Game
Backdoors & Breaches: backdoorsandbreaches.com
Play B&B Online: play.backdoorsandbreaches.com
///Antisyphon Training
Pay What You Can: antisyphontraining.com/pay-what-you-can
Live Training: antisyphontraining.com/course-catalog
On Demand Training: antisyphontraining.com/on-demand-course-catalog
Antisyphon Discord: discord.gg/antisyphon
Antisyphon Mastodon: https://infosec.exchange/@Antisy_Training
///Educational Infosec Content
Black Hills Infosec Blogs: blackhillsinfosec.com/blog
Wild West Hackin' Fest YouTube: youtube.com/wildwesthackinfest
Antisyphon Training YouTube: youtube.com/antisyphontraining
Active Countermeasures YouTube: youtube.com/activecountermeasures
Threat Hunter Community Discord: discord.gg/threathunter
Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — Wild West Hackin' Fest: wildwesthackinfest.com
Web Application Authorization: Taming the Perfect Storm
Presenter: Tim Tomes
Access control vulnerabilities are everywhere. Across my last 40 web application security assessments, I identified 41 access control related findings, which means almost every modern application has at least one serious flaw. This aligns with OWASP, which ranks Broken Access Control as the number one risk facing web applications today. But why is this problem so persistent?
The simple answer is that access control is difficult. It is difficult to design, difficult to implement, difficult to maintain, and difficult to test. When these challenges collide, they create the perfect storm for privilege escalation and unintended data exposure. However, those who deeply understand these systems and know how to evaluate them can turn this storm into an advantage.
In this talk, I will help you build that skillset. We will explore the most common pitfalls across different application architectures, and I will walk through the tools and techniques I use to uncover access control flaws in real systems. We will also cover practical remediation approaches and discuss how development teams can automate access control testing within a CI/CD pipeline, which many still believe to be impossible.
Sign Up for WWHF
wildwesthackinfest.com/register
#appsec #websecurity #owasp #brokenaccesscontrol #pentesting #securitytesting #infosec #cybersecurity #wwhf #wwhf2026
///Black Hills Infosec Socials
Twitter: twitter.com/BHinfoSecurity
Mastodon: https://infosec.exchange/@blackhillsinfosec
LinkedIn: linkedin.com/company/antisyphon-training
Discord: discord.gg/ffzdt3WUDe
///Black Hills Infosec Shirts & Hoodies
spearphish-general-store.myshopify.com/collections/bhis-shirt-collections
///Black Hills Infosec Services
Active SOC: blackhillsinfosec.com/services/active-soc
Penetration Testing: blackhillsinfosec.com/services
Incident Response: blackhillsinfosec.com/services/incident-response
///Backdoors & Breaches - Incident Response Card Game
Backdoors & Breaches: backdoorsandbreaches.com
Play B&B Online: play.backdoorsandbreaches.com
///Antisyphon Training
Pay What You Can: antisyphontraining.com/pay-what-you-can
Live Training: antisyphontraining.com/course-catalog
On Demand Training: antisyphontraining.com/on-demand-course-catalog
Antisyphon Discord: discord.gg/antisyphon
Antisyphon Mastodon: https://infosec.exchange/@Antisy_Training
///Educational Infosec Content
Black Hills Infosec Blogs: blackhillsinfosec.com/blog
Wild West Hackin' Fest YouTube: youtube.com/wildwesthackinfest
Antisyphon Training YouTube: youtube.com/antisyphontraining
Active Countermeasures YouTube: youtube.com/activecountermeasures
Threat Hunter Community Discord: discord.gg/threathunter
Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — Wild West Hackin' Fest: wildwesthackinfest.com










