πŸ₯ MedPortal Patient System

Secure Medical Records Database

⏱️ Request Performance Metrics

Patient ID: 2000

Query Time: 2198ms

Database Status: Connected

Server Load: Normal

πŸ”’ Access Restricted

Patient ID "2000" exists but you don't have permission to view this record.

🎯 Hunter Objective:
πŸ• Response Time Patterns

Timing Analysis Guide:

  • ~89ms - Non-existent ID (immediate rejection)
  • ~1456ms - Valid patient (standard database query)
  • ~2198ms - Restricted patient (security checks)
  • ~2847ms - Admin account (audit logging + permissions)
🚨 Side-channel timing IDOR vulnerability | Let's Jam Training Platform