Monday, December 10, 2007

Passport Canada Exposed

This one is too easy. In fact, it's so easy it's scary. It's just URL manipulation. Yep, URL manipulation. And, I'll bet you thought that went out with floppy disk viruses.

But someone applying for a passport in Canada discovered the flaw by just manipulating numbers in the URL of his online application. The applicant was able to pull up other applications on line.

Here are some details with screen shots.



