![]() |
|
| Domain Name Sales | Domain Software | Calculate UK Domain Drop Dates | Domain Registration | SedoPro Code | Domains For Sale | NameDrive | Domain Parking |
|
|||||||
| Sedo Buying, Selling, Parking Domains with Sedo - Sign up for an account |
![]() |
|
|
LinkBack | Thread Tools | Display Modes |
|
|
#1 (permalink) |
![]() |
How's this for security
I pressed a link to a sedo auction, and not only did it take me to the auction, it also logged me into the sellers account where I was free to browse his domains or do whatever I liked with his account.
=Screenshot removed at the request of Sedo= Now that's what I call security ![]() Suppose posting the Session ID in the link didn't help Last edited by retired member 1; 05-12-2006 at 09:01:14 AM. |
|
|
|
|
#6 (permalink) |
![]() |
|
|
|
|
|
#7 (permalink) |
![]() |
You'd think a cookie test would be in order?
__________________
Memorable Domains: Over 4,000 descriptive generic .co.uk domains for sale Important: All sale prices over 2 weeks old are automatically invalid. No exceptions. |
|
|
|
|
#8 (permalink) |
![]() |
one of the most interesting parts is nobody wants to look at colleen!!
|
|
|
|
|
#9 (permalink) |
|
Sedo Staff
|
Hi everyone,
Just had a talk with tech about this. As you are aware, if a session ID is posted anywhere and the user is online (meaning the session is still active), you will be logged into the other user's account. Obviously, this is not desirable. We will be switching to Cookie sessions in the near future to do away with this problem, as we certainly want to make sure our system is as secure as possible. Again, thank you for bringing this to our attention. Tech's working on the solution right now. Kind regards, Brad brad.tilley@sedo.com |
|
|
![]() |
| Bookmarks |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Domain Name Community | Replies | Last Post |
| sedo pro - how's your month going ?? | pendragon | Sedo | 18 | 26-11-2006 10:32:14 PM |