You can't secure what you don't acknowledge.SM

Wednesday, September 2, 2009

Interesting flaw in Sears' Web site all too common

Check out this bit about a security flaw recently revealed on Sears' Web site. As the researcher alluded to, hacking and security are way more than people exploiting known software flaws. There are so many other security issues with Web applications. I see it all the time when doing my manual analyses on Web sites/applications. The sky is the limit for these business logic vulnerabilities and I suspect it'll always be that way. I love being a consultant who performs Web security assessments - there's always something new and challenging!

No comments:

Post a Comment