Subscribe to Infosec Events
    Infosec Events Feed Stay up to date with all of the latest security news by subscribing to our RSS Feed. Alternatively, you can have updates sent directly to your email address.

    Profiting From Business Logic Flaws

    Published: August 8th, 2008 | Category: Security Conferences

    Yesterday Jeremiah Grossman and Trey Ford from WhiteHat Security gave a very interesting and fun presentation called ‘Get Rich or Die Trying – Making Money on The Web, The Black Hat Way‘. They went over several real world examples of business logic flaws, and in some cases profited (a lot) from those flaws.

    The Get Rich or Die Trying slides are now online at slideshare.net. After reviewing the slides, I remembered the Pepsi contest back in 2005 where they were giving away an Xbox 360 every 10 minutes. The hacks resulted in a 99% chance of winning an Xbox 360 in the contest. I’m not sure how many people ‘won’ an Xbox 360 in this method, but it took the contest owner several days to fix the issue.

    Update: If you are in the Chicago Illinois area, Jeremiah will be doing an encore presentation at OWASP Chicago on August 21st.

    Be Sociable, Share!

      Tags: , , , , ,

      RSS feed | Trackback URI

      Comments »

      No comments yet.

      Name (required)
      E-mail (required - never shown publicly)
      URI
      Your Comment (smaller size | larger size)
      You may use <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong> in your comment.

      Trackback responses to this post

        © Godai Group 2013
        Home - Calendar - Communities - Training - Archives - Contact