Bountii on Bing Cashback: It's Broken
bountii.com
Bountii on Bing Cashback: It's Broken
1–9 of 9 posts
Re: Bountii on Bing Cashback: It's Broken
#2Re: Bountii on Bing Cashback: It's Broken
#32009 and they are using URLs to pass data? I thought there was a push for security at Microsoft?
Using a publically visible tracking cookie to pass transaction data, though...
Microsoft spends more on security per line-of-code shipped than any company in the world. I have no idea how something this bad could have shipped. But I don't know the whole story.
One possible explanation: web pest tools like Burp filter out images from the request history, because you usually don't bother fuzzing requests for images.
Of course, you usually don't embed dollar amounts in images either.
Re: Bountii on Bing Cashback: It's Broken
#4Re: Bountii on Bing Cashback: It's Broken
#52009 and they are using URLs to pass data? I thought there was a push for security at Microsoft?
Using URLs to pass data is fine, if skeevy. Using a publically visible tracking cookie to pass transaction data, though... Microsoft spends more on security per line-of-code shipped than any company in the world. I have no idea how something this bad could have shipped. But I don't know the whole story. One possible explanation: web pest tools like Burp filter out images from the request history, because you usually…
Re: Bountii on Bing Cashback: It's Broken
#6Earlier quoted context omitted.
Using URLs to pass data is fine, if skeevy. Using a publically visible tracking cookie to pass transaction data, though... Microsoft spends more on security per line-of-code shipped than any company in the world. I have no idea how something this bad could have shipped. But I don't know the whole story. One possible explanation: web pest tools like Burp filter out images from the request history, because you usually…
This is funny, but I doubt there is any actual security flaw. I expect that Microsoft will verify these transaction later on with the vendor and throw them out.
Re: Bountii on Bing Cashback: It's Broken
#7Earlier quoted context omitted.
Using URLs to pass data is fine, if skeevy. Using a publically visible tracking cookie to pass transaction data, though... Microsoft spends more on security per line-of-code shipped than any company in the world. I have no idea how something this bad could have shipped. But I don't know the whole story. One possible explanation: web pest tools like Burp filter out images from the request history, because you usually…
This is funny, but I doubt there is any actual security flaw. I expect that Microsoft will verify these transaction later on with the vendor and throw them out.
Re: Bountii on Bing Cashback: It's Broken
#8The funny thing is that Microsoft basically paid me about $200 to get a Mac (it was $200 because that's the max per transaction).
Re: Bountii on Bing Cashback: It's Broken
#9Earlier quoted context omitted.
This is funny, but I doubt there is any actual security flaw. I expect that Microsoft will verify these transaction later on with the vendor and throw them out.
I'm sure that is true. That's part of the reason it take so long to get paid; they're waiting until the window to return the merchandise expires. My BoA rewards program does the same thing.