Idatha yeTamper: Okungeziwe ku-Firefox

Abathuthukisi bezinhlelo zokusebenza zewebhu bavame ukwethemba ukuthi abasebenzisi abaningi bazolandela imithetho futhi basebenzise uhlelo lokusebenza njengoba kuhloswe ukuthi lisetshenziswe, kodwa kuthiwani uma umsebenzisi (noma i- hacker ) egoba imithetho? Kuthiwani uma umsebenzisi weqa isikhombimsebenzisi sewebhu esiyinkimbinkimbi futhi eqala ukuthungela phansi ngaphansi kwe-hood ngaphandle kwezinkinga ezibekwa yisiphequluli?

Kuthiwani Nge-Firefox?

I-Firefox yisiphequluli sokuzikhethela kubaduni abaningi ngenxa ye-plug-in design yayo enobungane. Elinye lamathuluzi we-hacker ethandwa kakhulu we-Firefox yi-add-on okuthiwa i-Tamper Data. I-Tamper Data ayiyona ithuluzi eliyinkimbinkimbi kakhulu, lingummeleli nje ozifaka phakathi komsebenzisi kanye newebhusayithi noma uhlelo lokusebenza lwewebhu abapheqululayo.

I-Tamper Data ivumela ukuthi i-hacker ihlise ikhethini ukuze ibuke futhi ihlaziye nayo yonke i-"magic" ye-HTTP eyenziwa ngemuva kwezigcawu. Wonke lawo ma-GET nama-POST angaphathwa ngaphandle kwezingqinamba ezibekwe isikhombikubona somsebenzisi esibonwe kusiphequluli.

Kuyini & # 39; s Ukuthanda?

Ngakho kungani abaduni befana neTamper Data kakhulu futhi kungani abathuthukisi bezinhlelo zokusebenza bewebhu kufanele bakhathalele ngakho? Isizathu esiyinhloko ukuthi ivumela umuntu ukuba adonsele idatha edluliselwa emuva naphakathi kweklayenti nesiphakeli (ngakho-ke igama elithi Tamper Data). Uma i-Tamper Data iqalile futhi uhlelo lokusebenza lwewebhu noma iwebhusayithi lusiwe ku-Firefox, i-Tamper Data izobonisa zonke izinsimu ezivumela ukufakwa komsebenzisi noma ukuphathwa kabi. I-hacker ingashintsha insimu ibe "ngenye indlela" futhi ithumele idatha kwisiphakeli ukuze ibone ukuthi iphendula kanjani.

Okwenza lokhu kube yingozi kulesicelo

Yisho i-hacker ivakashela isayithi lokuthengwa kwe- intanethi futhi ineza into ekuthengeni kuyo inqola yokuthenga. Umthuthukisi wesicelo sewebhu owakhile inqola yokuthenga kungenzeka ukuthi ukhonjise inqola ukwamukela inani kusuka kumsebenzisi njenge-Quantity = "1" futhi ukhawulele isici esibonakalayo somsebenzisi ebhokisini elidonsela phansi eliqukethe okhethiwe ngaphambilini.

I-hacker ingazama ukusebenzisa i-Tamper Data ukudlula imikhawulo ebhokisini lokudonsa elivumela kuphela abasebenzisi ukuba bakhethe kusukela kusethi lamanani afana ne "1,2,3,4," no-5. Ukusebenzisa i-Tamper Data, i-hacker zama ukungena okuhlukile kokuthi "-1" noma mhlawumbe ".000001".

Uma umthuthukisi engayibhalanga kahle isimiso sokuqinisekisa okufakwayo, khona-ke inani le- "-1" noma ".000001" lingase liphele ngokudluliselwa kumfomula osetshenziselwa ukubala izindleko zento (okuyi-Price x Inani). Lokhu kungaholela eminye imiphumela engalindelekile kuye ngokuthi ngabe ukuhlolwa kwephutha kuqhubeka kangakanani nokuthi ukuthembela kunjiniyela kunayo idatha evela kwiklayenti. Uma inqola yokuthenga ingekho ikhodi, khona-ke i-hacker ingase iqede ukuthola isaphulelo esikhulu esingalindelekile, ukubuyiselwa imali emkhiqizo abazange bakuthenge ngisho, isikweletu sesitolo noma ubani owaziyo okunye.

Amathuba okusebenzisa kabi uhlelo lokusebenza lwewebhu usebenzisa i-Tamper Data ayinakuphela. Uma ngabe ngingumthuthukisi we-software, nje ngiyazi ukuthi kukhona amathuluzi afana ne-Tamper Data ngaphandle angangigcina ebusuku.

Esikhathini se-flip-side, Idatha ye-Tamper iyithuluzi elihle kakhulu labalandeli bezinhlelo zokusebenza zokuphepha abazimele basebenzise ukuze bakwazi ukubona ukuthi izicelo zabo ziphendula kanjani ukuhlaselwa kwedatha yokuhlukunyezwa kwedatha.

Abathuthukisi bavame ukudala Ukusebenzisa Amacala Ukugxila ukuthi umsebenzisi angasebenzisa kanjani isofthiwe ukuze afeze umgomo. Ngeshwa, ngokuvamile bazinaki umqondo omubi womfana. Abathuthukisi be-App badinga ukufaka izigqoko zabo zababi futhi badale Amacala Okungalungi ukuba alandele abaduni basebenzisa amathuluzi afana neTamper Data.

Idatha ye-Tamper kufanele ibe yingxenye ye-arsenal yokuhlola yokuvikela ukusiza ukuqinisekisa ukuthi ukufakelwa komkhakha weklayenti kuvunyelwe futhi kuqinisekiswe ngaphambi kokuthi kuvumeleke ukuthi kuthinte ukuthengiselana nezinqubo zeseva. Uma abathuthukisi bengabambe iqhaza ekusebenziseni amathuluzi afana ne-Tamper Data ukuze abone ukuthi izinhlelo zabo ziphendula kanjani ukuhlasela, khona-ke ngeke bazi ukuthi yini ongayilindela futhi angaqeda ukukhokha lo mthethosivivinywa we-TV yamasentimitha angama-60 e-plasma lapho i-hacker nje bathengwe ngamasheya angu-99 basebenzisa inqola yabo yokuthenga engalungile.

Ukuze uthole ukwaziswa okwengeziwe kwi-Tamper Data Add-on ye-Firefox vakashela ikhasi le-Tamper Data Firefox ongezeko.