docs

Hugin BAC

Hugin — broken access control

Test broken access control: IDOR, BAC, authorization matrix, privilege escalation. This is where the highest-impact bugs often live.

Load the tools

Call tools/list with _meta.bundle = "bugclass-bac". You get: idor, bac, bac_audit, bac_matrix, authz, authz_audit, session, session_profiles, param_discover.

Load the skill fragment

Read MCP resource hugin://skill/bugclass-bac for the full workflow + gotchas.

Workflow

  1. Capture authenticated traffic — drive the target logged in as a low-priv user.
  2. Set up session profiles — call session_profiles to capture at least two identities (low-priv + admin if possible).
  3. Run idor — swaps ID parameters between identities, diffs responses.
  4. Run authz/bac — replays flows with different identities, checks for access leaks.
  5. Matrix test — use bac_matrix for systematic identity×endpoint coverage.
  6. Prove it — show the low-priv identity accessing admin data. Capture the request/response.

Rules

  • Authorised targets only. Stay in scope.
  • BAC testing needs multiple identities — set up session_profiles before testing.
  • IDOR is about response diffs — low-priv user getting a 200 where they should get 403.
  • Check both horizontal (same role, different user) and vertical (different role) escalation.
  • Don't just check status codes — diff the response body. A 200 with empty body is not a finding.
  • param_discover finds hidden parameters that may bypass access controls.
  • Evidence over assertion — capture the exact request/response showing the access violation.