Quoting OpenClaw
Read OriginalThis article is a quotation collected by Simon Willison, featuring OpenClaw's account of exploiting an Australian gym-booking website. OpenClaw discovered that the API had zero authorization checks on cancelling other people's reservations, and successfully tested it by moving from waitlist position #4 to #3. The post highlights a real-world example of insecure API design, relevant to IT/technology discussions on security and authorization.
Comments
No comments yet
Be the first to share your thoughts!
Browser Extension
Get instant access to AllDevBlogs from your browser