New account since lemmyrs.org went down, other @Deebsters are available.

  • 1 Post
  • 62 Comments
Joined 9 months ago
cake
Cake day: October 16th, 2023

help-circle


  • To fuzz this, I simply used Burp’s intruder to enumerate from %00 to %FF at the end of the URL.

    I like to think about what normal people would think when they read something like this. It sounds like a line from a cyberpunk wizard.

    We had confirmed that we could bypass authorization for the API endpoints by simply replaying the HTTP request multiple times

    Not really replaying, since his initial request worked. Feels like it’s going through a load balancer and one from that group of servers didn’t have authentication enabled (accidentally included a test/dev server, maybe).












  • Yeah, people definitely have a tendency to act entitled just because they’ve paid money.

    It reminds me of this story from Freakonomics:

    The economists decided to test their solution by conducting a study of ten day-care centers in Haifa, Israel. The study lasted twenty weeks, but the fine was not introduced immediately. For the first four weeks, the economists simply kept track of the number of parents who came late; there were, on average, eight late pickups per week per day-care center. In the fifth week, the fine was enacted. It was announced that any parent arriving more than ten minutes late would pay $3 per child for each incident. The fee would be added to the parents’ monthly bill, which was roughly $380.

    After the fine was enacted, the number of late pickups promptly went… up. Before long there were twenty late pickups per week, more than double the original average. The incentive had plainly backfired.