This post is a reference to one of the articles I curated for the API Magazine. Below is a short intro.
Moonpig are one of the most well known companies that sell personalised greeting cards in the UK. In 2007 they had a 90% market share and shipped nearly 6 million cards. In July 2011 they were bought by PhotoBox.
Manfred Bortenschlager’s comment:
Another API security exploit: the internal Moonpig API. In fact, non-existing security exploit.
“… there’s no authentication at all and you can pass in any customer ID to impersonate them. An attacker could easily place orders on other customers accounts, add/retrieve card information, view saved addresses, view orders and much more…”
Come on, API Providers, secure your APIs at least a bit. It is not such a big deal. And there are plenty of off-the-shelf, cost-effective API Management solutions.