I wonder if this is similar to when weev & Goatse Security “hacked” AT&T by discovering that their website for managing iPad accounts was so poorly designed that you could just change the account number in the website’s URL to access other people’s accounts.
deleted by creator