Field notes from an authorized audit of a small web store. The headline: there was no backend to attack, so the real findings were identifier manipulation (business logic) and clickjacking. Setup / hypothesis Small store on Vercel: catalog, product pages, cart, share-cart URLs, contact buttons. Looked like Next.js. Turned out to be a React + Vite... Weiterlesen
Intelligence View
⚡ tsecurity.de Intelligence
Authorized Web Audit: When the App Has No Backend, You Audit Its Assumptions
Field notes from an authorized audit of a small web store. The headline: there was no backend to attack, so the real findings were identifier manipulation…