←back to thread

134 points shinzub | 1 comments | | HN request time: 0.376s | source
Show context
joshfraser ◴[] No.42743865[source]
Back in 2013 I discovered that you could use clickjacking to trick someone into buying anything you wanted from Amazon (assuming they were signed in). It took them almost a year to fix the issue. They never paid me a bounty.

https://onlineaspect.com/2014/06/06/clickjacking-amazon-com/

replies(2): >>42744403 #>>42744621 #