Are your prices valid?
Heres a really silly problem that could be a major issue for your Web site: Hackers changing prices when they buy.
The way it works is pretty simple. Youre selling, say, a book for $14. The hacker saves the page that submits the purchase to the shopping cart and edits the price to, say, $1.40 in the saved page, and then uses a browser or HTML editor to publish the page to the URL that accepts the form.
The result for many sites is an erroneous shopping cart that can be processed as if it were real. Worse still, price alterations are often not caught when the basket is checked out -- indeed, the fraud may not be detected until the next audit!
So, make sure your Web ordering system checks prices as items are added to the shopping cart and then check them again on checkout.
Let me know if your Web site is immune to this problem, and if thats because youve been caught by this hack. I promise not to tell anyone.
» posted by ITworld staff
Network World
Sign up for ITworld's Daily newsletter
Follow ITworld on Twitter @IT_world
jfruh
Apple syncing patent can't come soon enough
pasmith
New Twitter features borrow from 3rd party clients
Esther Schindler
Open Source Changes the Software Acquisition Process
mikelgan
How to set up continuous podcast play on the new iTunes
David Strom
Five important Windows 7 mobility features
sjvn
Guard your Wi-Fi for your own sake
Sandra Henry-Stocker
Grepping on Whole Words
Sidekick: The Good News & the Bad News
Either way you look at it Microsoft Data Center management did not follow standards or best practices in this failure. In which case it makes me wonder more about the outsourcing of corporate data much less personal data.
- mburton325
Join the conversation here
Quick, practical advice for IT pros. Made fresh daily.
Want to cash in on your IT savvy? Send your tip to tips@itworld.com. If we post it, we'll send you a $25 Amazon e-gift card.













