zerodom_compare_identities
Fetch a URL under multiple identities and compare responses to identify cross-tenant IDOR vulnerabilities through byte-identical matches.
Instructions
Fetch one URL as each identity and diff — the cross-tenant IDOR check.
Sends method url through every identity in identities (default: the
live session plus every registered one) and reports each response's status
and size. A byte-identical response under two identities on a per-user
resource is a cross-tenant IDOR. Runs on the real, rendered session, so it
works where a plain HTTP fetch would hit a WAF or a login wall.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| url | Yes | ||
| body | No | ||
| method | No | GET | |
| identities | No |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |