3 ms·
Low hanging fruit that seemed somewhat common back in the day was not verifying prices of items on the backend. So a somewhat technical user could edit the pri
by Shocka1 2y ago
Low hanging fruit that seemed somewhat common back in the day was not verifying prices of items on the backend. So a somewhat technical user could edit the price in the html field of the item to be $10 instead of $100.
Between this and everything being non https - what a time to be alive.
- knodi123 2y agoIIRC, an early version of myspace actually used a GET form for login. It immediately redirected, but if your browser was wide enough, and your eye was trained on the address bar and knew what to look for, you'd see the password flash by in plaintext.
- dsauerbrun 2y agowhy is that an issue? just in case someone is peering over your shoulder? the pw will be sent in the request body as plaintext on a post...
- knodi123 2y ago> just in case someone is peering over your shoulder Yes, exactly that. That's why I highlighted the risk of someone looking in the right spot at the right time. > the pw will be sent in the request body as plaintext on a post Which is how every single login form in the world works, today, for this very reason.