post

Web Security: How to buy a 65” Plasma for $.99

I have no clue if this is real:  Edgeblog describes a way to change the price on certain shopping sites using the CartIt.cgi shopping app before the item is submitted to the server.

He than goes on:

Doing a simple Google search for cartit.cgi+plasma, I found a web site that sells plasma TVs (Which shall remain nameless to prevent being sued). The website thinks it is selling TVs for $7,599, but we can pay whatever we want by intercepting the POST and changing the price. If you think the company would catch this error, think again. Many companies outsource the fulfillment of orders, and never check the prices being charged. Note: I do not endorse e-shoplifting, so I did not complete the above transaction, but I know for a fact that the site will accept the order for $.99. Now, $.99 is extreme enough to *maybe* raise a flag. A simpler approach is to just move the decimal over 1 or 2 places. This way, if the company does notice, they will assume it was a processing error on their side. So maybe this article should be titled: “How to buy a 65″ plasma for $75.99.”

Wow.

 

Comments

  1. Zoli,

    Thanks for picking up my blog article. I assure you it is real. Sadly, there are a lot of unsuspecting small businesses using the crappy shopping carts provided by their hosting companies. Keep up the great work on your blog.

    -Bill

%d bloggers like this: