OWASP AppSensor

OWASP AppSensor - An OWASP incubator project

About OWASP AppSensor

RE3: GET When Expecting POST

IDRE3
TitleGET When Expecting POST
CategoryRequestException
DescriptionA page which is expecting only POST requests, is requested by HTTP method GET.
ConsiderationsSome pages may be designed to receive both GET and POST requests.
TuningSome resources may allow both GET and POST methods e.g. an edit form may be hyperlinked using a parameter value defining the record to be edited, but the form is submitted by POST to itself. Users may bookmark a page that is the result of a POST and return to it at a later date.
ExamplesThe user sends a GET request to a page which has only been used for POSTs.
CodeJava .Net PHP

RE4: POST When Expecting GET

IDRE4
TitlePOST When Expecting GET
CategoryRequestException
DescriptionA page which is expecting only GET requests, receives a POST.
Considerations\-
Tuning(same as RE3)
ExamplesThe user utilizes a proxy tool to build a custom POST request and sends it to a page which has been accessed by GET requests.
CodeJava .Net PHP

AE10: Additional POST Variable

IDAE10
TitleAdditional POST Variable
CategoryAuthenticationException
DescriptionAdditional, unexpected POST variables are received during an authentication request.
Considerations\-
Tuning(same as RE5)
ExamplesThe user utilizes a proxy tool to add the POST variable of 'admin=true' to the request.
CodeJava .Net PHP

AE11: Missing POST Variable

IDAE11
TitleMissing POST Variables
CategoryAuthenticationException
DescriptionExpected POST variables are not present within the submitted authentication request.
Considerations\-
Tuning(same as RE6)
ExamplesThe user utilizes a proxy tool to remove an additional POST variable, such as 'guest=true', from the POST request.
CodeJava .Net PHP

ACE2: Modifying Parameter Within A POST for Direct Object Access Attempt

IDACE2
TitleModifying Parameter Within A POST for Direct Object Access Attempt
CategoryAccessControlException
DescriptionThe value of a non-free text html form element (i.e. drop down box, radio button) is modified to an illegal value. The value either does not exist or is not authorized for the user.
Considerations\-
Tuning(same as ACE1 for bookmarking)
ExamplesThe user utilizes a proxy tool to intercept a POST request and changes the submitted value to a value that was not available through the normal display. For example, the user encounters a dropdown box containing the numbers 1 through 10. The user selects 5 and then intercepts the request to change the submitted value to 100.
CodeJava .Net PHP

ACE4: Evading Presentation Access Control Through Custom POST

ID|ACE4 Title|Evading Presentation Access Control Through Custom POST Category|AccessControlException Description|A POST request is received which is not authorized for the current user and the user could not have performed this action without crafting a custom POST request. Considerations|This situation is most likely to occur when presentation layer access controls are in place and have removed the user's ability to initiate the action through the presentation of the application. An attacker may be aware of the functionality and attempt to bypass this presentation layer access control by crafting their own custom message and sending this in an attempt to execute the functionality. Tuning|\- Examples|The application contains the ability for an administrator to delete a user. This method is normally invoked by entering the username and submitting to Presentation layer access controls ensure the delete user form is not displayed to non-administrator users. A malicious user has access to a non-administrator account and is aware of the delete user functionality. The malicious user sends a custom crafted POST message to in an attempt to execute the delete user method. Code|[Java](http://www.owasp.org/index.php/AppSensor_DetectionPoint_ACE4#java) [.Net](http://www.owasp.org/index.php/AppSensor_DetectionPoint_ACE4#net) [PHP](http://www.owasp.org/index.php/AppSensor_DetectionPoint_ACE4#php)

Project Leaders

ized information

ized for that user

ized for the user

ized to download/view

ised (i

ised deletion of

changes

isation

isation by bank staff

ised

John Melton

Project Leader

Email

Project Information

Incubator Project
Classification
Other
Language
JavaScript
License
MIT License
Contributors
19
GitHub Stars
287
Downloads
0
OWASP Logo
OWASP is a nonprofit foundation improving software security through open-source projects, global communities, and education. All resources are free and open to everyone.
OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc.
© 2026, OWASP Foundation Inc. All rights reserved.
OWASP AppSensor | OWASP Foundation