This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Difference between revisions of "Talk:Testing for business logic"
From OWASP
(Description of Issues - Example 2) |
m (→Description of Issues - Example 2) |
||
Line 3: | Line 3: | ||
There something missing in Example 2. You've jumped from altering preferences to taking ownership of accounts. | There something missing in Example 2. You've jumped from altering preferences to taking ownership of accounts. | ||
− | I can understand that if I was editing preferences and sent userid 818 I'd alter the preferences of another company's user but how would ownership of that account change? | + | I can understand that if I was editing preferences and sent userid 818 I'd alter the preferences of another company's user but how would ownership of that account change? [[User:Rick.mitchell|Rick.mitchell]] 08:42, 25 June 2008 (EDT) |
Revision as of 12:42, 25 June 2008
Description of Issues - Example 2
There something missing in Example 2. You've jumped from altering preferences to taking ownership of accounts.
I can understand that if I was editing preferences and sent userid 818 I'd alter the preferences of another company's user but how would ownership of that account change? Rick.mitchell 08:42, 25 June 2008 (EDT)