I found a flaw in the Apple Store page and they fixed it without saying “Thanks”(bozhkoff.com)
bozhkoff.com
I found a flaw in the Apple Store page and they fixed it without saying “Thanks”
http://bozhkoff.com/i-told-apple-about-a-security-flaw-in-their-product-page-and-they-fixed-it-without-as-much-as-saying-thanks/
4 comments
How is this a security flaw?
This is seems to be a case of "Missing Function Level Access Control"[0] as defined by the Open Web Application Security Project (OWASP).
I highly suggest browsing OWASP's Top 10[1] if you are a software developer and believe this is not a security vulnerability.
[0] https://www.owasp.org/index.php/Top_10_2013-A7-Missing_Funct...
[1] https://www.owasp.org/index.php/Top_10_2013-Top_10
I highly suggest browsing OWASP's Top 10[1] if you are a software developer and believe this is not a security vulnerability.
[0] https://www.owasp.org/index.php/Top_10_2013-A7-Missing_Funct...
[1] https://www.owasp.org/index.php/Top_10_2013-Top_10
No offense but no you didn't, this is internet garbage thanks don't post anymore
Further, the email starts off with,
"Thank you for contacting the Apple Product Security team."