L
L
LookAtIos2019-01-17 08:57:03
Online shopping
LookAtIos, 2019-01-17 08:57:03

Is it possible to brute-force guess a coupon in an online store?

An interesting idea has come up. I found an extension that substitutes a username and password in the browser, and decided to apply it to an online store with coupons. There is no captcha, not even a limit on the input field. Just out of curiosity, can I find the coupons they have in the database? The speed of requests can be adjusted, I'll set it to about 10 seconds.
And the next question is, are there any dictionaries for this case?
p.s. is this legal?

Answer the question

In order to leave comments, you need to log in

1 answer(s)
D
Developer, 2019-01-17
@samodum

Of course you can guess. The question is what format these coupon codes are and how long it takes to sort through them.
There is nothing illegal in the enumeration itself, if this action did not affect the performance of the site. Unless, of course, this is specifically specified in the ToS or other documents.
The problem may arise if you want to somehow use these coupon codes, what damage you will cause to the company, and it also depends on the reaction of the company itself to this matter

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question