Vertical privilege escalation
occurs when a user can perform functions
that their assigned role does not permit them to. For example, if an
ordinary user can perform administrative functions or a clerk is able to
pay invoices of any size, then access controls are broken.
■■
Horizontal privilege escalation
occurs when a user can view or modify
resources to which he is not entitled. For example, if you can use a web
mail application to read other people’s email, or if a payment clerk can
process invoices for an organizational unit other than his own, then
access controls are broken.
Do'stlaringiz bilan baham: |