What is Parameter Tampering and Temptation Attack in Penetration Testing & Cybersecurity?

Understanding Parameter Temptation and Tampering

Parameter temptation is a process where the parameters found during pentesting are tampered with or modified to change the output. 

Sometimes, the hackers manipulate the URL parameters to find the details or data that was supposed to remain unavailable to end-users. The risks of the parameter temptation depend on which parameters are being tampered with. 

The aim of doing parameter temptation can be to access the files above the web root, find database information and run arbitrary OS commands. 

For example, attackers try parameter temptation of eCommerce sites to change the pricing of the product being ordered. 

Testing Advance Parameter Temptation

