Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I remember a number of early e-commerce sites that put item prices in HTML forms. So craft your own POST, and name your own price.


Yes, seen this once before, where the shipping price was calculated client side, then sent to the server with no validation. You could craft a request with a negative value and get the price down to a cent for the entire cart!

At least in e-commerce, you can always send an email to the customer explaining the mistake, and cancel the order...


Recently seen the price listed/editable in the URL on a checkout form page.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: