Thursday, February 27, 2014

Someone forgot to test the password function properly for Amazon

So, take as many guesses as you like.

If users enter their password incorrectly 10 times on the Amazon.com website, the company requires them to solve the squiggle of characters known as a CAPTCHA 

But Amazon.com did not show a CAPTCHA on its mobile applications for the iOS and Android platforms, allowing unlimited guesses, according to FireEye researchers Min Zheng, Tao Wei and Hui Xue.


The link below has more details:

http://www.pcworld.com/article/2102640/amazoncom-security-slip-allowed-unlimited-password-guesses.html

No comments:

Post a Comment