Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You can edit the content of any web site via the browser's dev tools. It's not hard. This only changes it locally, although it can have effects on poorly designed sites.

I have used this to buy tickets to an event for $1.



I once bought something with AJAX requests.

No, it wasn't unfair to the vendor. The vendor had an issue on a web site where the sales window closed, presumably to give the vendor time to process sales and print/mail tickets, but this was enforced front-end only. I was mid-check-out when the window closed with no warning.

There were plenty of tickets left. There was plenty of time left too (the vendor had switched from paper to digital tickets for COVID19, so...).

I think there was an exploitable security bug in there too, but I don't think anyone will exploit it. It's a little shop.


I was acquainted with the person who ran the event and website and let them know about the vulnerability and bought the tickets at the appropriate price after.

He was also storing passwords as plain text (they would email your password when you clicked "lost password?")... which is pretty troubling for a site that was also taking credit card payments.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: