Test for access control vulnerabilities by comparing HTTP responses across two sessions. The #1 bug class in bug bounty.