This should be a store application that lets them buy things. Additionally their purchase token will be stored in here. Let’s allow some Appsec vuln to leak the token, but don’t make it easily readable from the filesystem.
Should generate the team’s token based on user login credentials, so that it isn’t stored on disk and that way is harder to steal. Then introduce an appsec vuln to allow you to impersonate another user, or gain access to the app.
This app should allow them to buy things from white team, but the public facing unauthenticated portion should allow people (probably us) to buy things from them to earn them some extra money.
-- Kyle Caretto 2017
-
Notifications
You must be signed in to change notification settings - Fork 0
RITSPARSA/ISTS16-ECommerce
Folders and files
Name | Name | Last commit message | Last commit date | |
---|---|---|---|---|
Repository files navigation
About
Ecommerce site for ISTS 16
Resources
Stars
Watchers
Forks
Releases
No releases published
Packages 0
No packages published