且构网

分享程序员开发的那些事...
且构网 - 分享程序员编程开发的那些事

你见过的最糟糕的安全漏洞?

更新时间:2023-10-26 13:15:34

一个在线文档管理器怎么样,它允许设置你能记住的每一个安全权限......

How about an online document manager, which allowed to set every security permission you could remember...

直到您进入下载页面... download.aspx?documentId=12345

That is until you got to the download page... download.aspx?documentId=12345

是的,documentId 是数据库 ID(自动递增),您可以循环每个数字,任何人都可以获取所有公司文档.

Yes, the documentId was the database ID (auto-increment) and you could loop every single number and anyone could get all the company documents.

当收到此问题的警报时,项目经理的反应是:好的,谢谢.但是之前没有人注意到这一点,所以让我们保持原样.

When alerted for this problem the project manager response was: Ok, thanks. But nobody has noticed this before, so let's keep it as it is.