Thread Content
8.23--In the CAESARII version, those who answer correctly in the knowledge quiz receive 10 units of wealth, while those who answer incorrectly get 3 units of wealth. A security incident recently occurred on a certain e-commerce website, where an item worth 1000 yuan was purchased for just 1 yuan. Analysis revealed that this was due to the use of the Http protocol for browsing purposes, as a performance optimization measure during design; attackers were able to modify the price of items added to the shopping cart by forging data packets. Taking advantage of this vulnerability, attackers added items worth 1000 yuan to the shopping cart at a cost of 1 yuan each, and since there was no verification process during payment, this problem occurred. An analysis of the causes of this issue on the website, along with solutions, is provided. What is the most accurate statement? A. This issue arose due to the use of insecure protocols; to prevent similar problems from occurring again, the entire website needs to be upgraded for security, with all accesses requiring the use of HTTPS. B. This issue occurred because no proper work such as threat modeling was carried out before the website was developed, resulting in those threats going unidentified and no corresponding measures taken to address them. C. This issue was caused by coding defects, and it can be resolved by making modifications to the website so that product prices are verified during order payment. D. This isn’t a problem with the website; instead, the police should be called to intervene and punish the attackers
B. This issue arose because relevant tasks such as threat modeling were not carried out or were not done properly before website development, resulting in the failure to identify that threat and take appropriate mitigation measures
B. This issue arose because relevant tasks such as threat modeling were not carried out or were not done properly before website development, resulting in the failure to identify that threat and take appropriate mitigation measures
B. This issue arose because relevant tasks such as threat modeling were not carried out or were not done properly before website development, resulting in the failure to identify that threat and take appropriate mitigation measures