The Web Application Hacker’s Handbook Discovering and Exploiting Security Flaws


suitable balance has been accrued that can actually be extracted



Download 5,76 Mb.
Pdf ko'rish
bet627/875
Sana01.01.2022
Hajmi5,76 Mb.
#293004
1   ...   623   624   625   626   627   628   629   630   ...   875
Bog'liq
3794 1008 4334

suitable balance has been accrued that can actually be extracted.

Example 7: Cheating on Bulk Discounts

The authors encountered this logic flaw in the retail application of a software

vendor.

The Functionality

The application allowed users to order software products and qualify for bulk

discounts if a suitable bundle of items was purchased. For example, users who

purchased an antivirus solution, personal firewall, and anti-spam software

were entitled to a 25% discount on their individual prices.

The Assumption

When a user added an item of software to his shopping basket, the application

used various rules to determine whether the bundle of purchases he had cho-

sen entitled him to any discount. If so, the prices of the relevant items within

the shopping basket were adjusted in line with the discount. The developers

assumed that the user would go on to purchase the chosen bundle and so be

entitled to the discount.

The Attack

The developers’ assumption is rather obviously flawed and ignores the fact

that users may remove items from their shopping baskets after they have been


Download 5,76 Mb.

Do'stlaringiz bilan baham:
1   ...   623   624   625   626   627   628   629   630   ...   875




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish