A recent question from my friend and colleague Mohammad got me thinking about the way we identify data in web applications.
While working on the DBIC component of a REST API, he came across the term enumeration attack. In this type of attack, an attacker systematically guesses resource identifiers in order to access...