Hugin BAC
Hugin — broken access control
Test broken access control: IDOR, BAC, authorization matrix, privilege escalation. This is where the highest-impact bugs often live.
Load the tools
Call tools/list with _meta.bundle = "bugclass-bac". You get: idor, bac,
bac_audit, bac_matrix, authz, authz_audit, session, session_profiles,
param_discover.
Load the skill fragment
Read MCP resource hugin://skill/bugclass-bac for the full workflow + gotchas.
Workflow
- Capture authenticated traffic — drive the target logged in as a low-priv user.
- Set up session profiles — call
session_profilesto capture at least two identities (low-priv + admin if possible). - Run idor — swaps ID parameters between identities, diffs responses.
- Run authz/bac — replays flows with different identities, checks for access leaks.
- Matrix test — use
bac_matrixfor systematic identity×endpoint coverage. - Prove it — show the low-priv identity accessing admin data. Capture the request/response.
Rules
- Authorised targets only. Stay in scope.
- BAC testing needs multiple identities — set up
session_profilesbefore testing. - IDOR is about response diffs — low-priv user getting a 200 where they should get 403.
- Check both horizontal (same role, different user) and vertical (different role) escalation.
- Don't just check status codes — diff the response body. A 200 with empty body is not a finding.
param_discoverfinds hidden parameters that may bypass access controls.- Evidence over assertion — capture the exact request/response showing the access violation.