Things for a security company not to do in a webapp: 1. Do not auto-populate form fields on the page with customer names.
2. If you ignore rule number 1, don't use a simple, predictable id for said auto-population. https://download.foundstone.com/?o=^2155 Rinse, increment, and repeat for a list of Foundstone customers...or at least a list of companies they've let download software. Now that's just plain sloppy. Concerned about your privacy? Instantly send FREE secure email, no account required http://www.hushmail.com/send?l=480 Get the best prices on SSL certificates from Hushmail https://www.hushssl.com?l=485 _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/