codehydra.com | Innovation through brute force

Apr/10

23

Validate ALL input!!!

Today one of the new guys at work ask me a question.  “Can our web portal submit “Severity 1″ support request?”

The standard answer has always been ‘No.”, but today I figured it was time to test that.

Start Tamperdata and log into the portal.  Dispatch request as normal with one exception.  change ‘severity’ value to 1 and submit. you now have a ‘sev1d’ support request without a phone call.

Software:

Firefox with Tamperdata add-on

No tags

No comments yet.

Leave a Reply

You must be logged in to post a comment.

<<

>>

Theme Design by devolux.nh2.me