Lesson Plan Title: How to Exploit Hidden Fields
Concept / Topic To Teach:
Developers will use hidden fields for tracking, login, pricing, etc.. information on a loaded page. While this is a convienent and easy mechanism for the developer, they often don't validate the information that is received from the hidden field. This lesson will teach the attacker to find and modify hidden fields to obtain a product for a price other than the price specifiedGeneral Goal(s):
The user should be able to exploit a hidden field to obtain a product at an incorrect price.