Automated A-B Testing
Last updated
Was this helpful?
Last updated
Was this helpful?
We can also use Burp's extension, in which we pass a low-privileged account's cookie and then browse the application as a high-privileged user. The extension then repeats each request made with the latter user as both a low-privileged and an unauthenticated user (Figure 2).
To test access control issues on things other than headers, such as like UUIDs in the URL path, we can use Burp's extension in a as Autorize.