This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "Talk:Testing for business logic"

From OWASP
Jump to: navigation, search
(Description of Issues - Example 2)
 
m (Description of Issues - Example 2)
Line 3: Line 3:
 
There something missing in Example 2. You've jumped from altering preferences to taking ownership of accounts.
 
There something missing in Example 2. You've jumped from altering preferences to taking ownership of accounts.
  
I can understand that if I was editing preferences and sent userid 818 I'd alter the preferences of another company's user but how would ownership of that account change?
+
I can understand that if I was editing preferences and sent userid 818 I'd alter the preferences of another company's user but how would ownership of that account change? [[User:Rick.mitchell|Rick.mitchell]] 08:42, 25 June 2008 (EDT)

Revision as of 12:42, 25 June 2008

Description of Issues - Example 2

There something missing in Example 2. You've jumped from altering preferences to taking ownership of accounts.

I can understand that if I was editing preferences and sent userid 818 I'd alter the preferences of another company's user but how would ownership of that account change? Rick.mitchell 08:42, 25 June 2008 (EDT)