Re: [FD] Ignore the amount customers confirm is no security vulnerability according to PayPal

2014-07-17 Thread Jan Kechel
-BEGIN PGP SIGNED MESSAGE- Hash: RIPEMD160 On 07/17/2014 09:47 PM, Glen Roberts wrote: > Just because they deny it does not mean you did not unveil a valid bug. > Personally, if a "feature" like this was really intended, I'd like to see the Paypal documentation where they highlight the u

Re: [FD] Ignore the amount customers confirm is no security vulnerability according to PayPal

2014-07-17 Thread Glen Roberts
Just because they deny it does not mean you did not unveil a valid bug. Personally, if a "feature" like this was really intended, I'd like to see the Paypal documentation where they highlight the utility and limits of such a function. Since when did alteration of data and integrity issues cease to

[FD] Ignore the amount customers confirm is no security vulnerability according to PayPal

2014-07-17 Thread Jan Kechel
-BEGIN PGP SIGNED MESSAGE- Hash: RIPEMD160 ** Title: ** Transfer any amount regardless of what customer confirmed ** Short description: ** In PayPal Express Checkout the Online-Shop can transfer any amount, n