Buy Sell Discuss UK Domain Names at AcornDomains.co.uk UK Cheapest

  All times are GMT. The time now is 07:45:54 PM.
Domain Name Sales Domain Software Calculate UK Domain Drop Dates Domain Registration SedoPro Code Domains For Sale NameDrive Domain Parking
Go Back   Domain Forum Acorn Domains Buy Sell Auction UK Domains > Domain Parking > Sedo

Sedo Buying, Selling, Parking Domains with Sedo - Sign up for an account

Closed Thread
 
LinkBack Thread Tools Display Modes
Old 04-12-2006, 03:45:12 PM     #1 (permalink)

 
Join Date: Apr 2005
Posts: 759
retired member 1 has a reputation beyond reputeretired member 1 has a reputation beyond reputeretired member 1 has a reputation beyond reputeretired member 1 has a reputation beyond reputeretired member 1 has a reputation beyond reputeretired member 1 has a reputation beyond reputeretired member 1 has a reputation beyond reputeretired member 1 has a reputation beyond reputeretired member 1 has a reputation beyond reputeretired member 1 has a reputation beyond reputeretired member 1 has a reputation beyond repute

How's this for security

I pressed a link to a sedo auction, and not only did it take me to the auction, it also logged me into the sellers account where I was free to browse his domains or do whatever I liked with his account.

=Screenshot removed at the request of Sedo=

Now that's what I call security

Suppose posting the Session ID in the link didn't help

Last edited by retired member 1; 05-12-2006 at 09:01:14 AM.
retired member 1 is offline  
Old 04-12-2006, 04:09:19 PM     #2 (permalink)

 
ratboy's Avatar
 
Join Date: Sep 2005
Posts: 1,815
ratboy has a reputation beyond reputeratboy has a reputation beyond reputeratboy has a reputation beyond reputeratboy has a reputation beyond reputeratboy has a reputation beyond reputeratboy has a reputation beyond reputeratboy has a reputation beyond reputeratboy has a reputation beyond reputeratboy has a reputation beyond reputeratboy has a reputation beyond reputeratboy has a reputation beyond repute

Jesus. discount the good uns and go buying...!!
ratboy is offline  
Old 04-12-2006, 04:15:19 PM     #3 (permalink)

 
Join Date: May 2005
Posts: 589
Nigel has a reputation beyond reputeNigel has a reputation beyond reputeNigel has a reputation beyond reputeNigel has a reputation beyond reputeNigel has a reputation beyond reputeNigel has a reputation beyond reputeNigel has a reputation beyond reputeNigel has a reputation beyond reputeNigel has a reputation beyond reputeNigel has a reputation beyond reputeNigel has a reputation beyond repute

Thanks for this info J2. I suppose the answer is to not let any domains go to Auction until Sedo confirm that this appalling glitch is sorted.
Nigel is offline  
Old 04-12-2006, 04:18:34 PM     #4 (permalink)
rob

 
rob's Avatar
 
Join Date: Jan 2005
Posts: 4,593
rob has a reputation beyond reputerob has a reputation beyond reputerob has a reputation beyond reputerob has a reputation beyond reputerob has a reputation beyond reputerob has a reputation beyond reputerob has a reputation beyond reputerob has a reputation beyond reputerob has a reputation beyond reputerob has a reputation beyond reputerob has a reputation beyond repute

I think it is if someone posts the URL themselves.

I have had something similar when someone sent me a portfolio link - which had them still logged in!
rob is offline  
Old 04-12-2006, 04:46:56 PM     #5 (permalink)

 
Join Date: Apr 2005
Posts: 759
retired member 1 has a reputation beyond reputeretired member 1 has a reputation beyond reputeretired member 1 has a reputation beyond reputeretired member 1 has a reputation beyond reputeretired member 1 has a reputation beyond reputeretired member 1 has a reputation beyond reputeretired member 1 has a reputation beyond reputeretired member 1 has a reputation beyond reputeretired member 1 has a reputation beyond reputeretired member 1 has a reputation beyond reputeretired member 1 has a reputation beyond repute

Yes, seller posted Session ID with the link, session ID's don't last forever, don't suppose there is much Sedo can do about it, it's up to the person posting the link to make sure there is no Session ID in the link.
retired member 1 is offline  
Old 04-12-2006, 05:23:31 PM     #6 (permalink)

 
olebean's Avatar
 
Join Date: Nov 2005
Location: Rarotonga
Posts: 2,272
olebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond repute

unbelievable
olebean is offline  
Old 04-12-2006, 09:18:34 PM     #7 (permalink)

 
Join Date: Apr 2005
Posts: 1,778
Edwin has a reputation beyond reputeEdwin has a reputation beyond reputeEdwin has a reputation beyond reputeEdwin has a reputation beyond reputeEdwin has a reputation beyond reputeEdwin has a reputation beyond reputeEdwin has a reputation beyond reputeEdwin has a reputation beyond reputeEdwin has a reputation beyond reputeEdwin has a reputation beyond reputeEdwin has a reputation beyond repute

You'd think a cookie test would be in order?
__________________
Memorable Domains: Over 4,000 descriptive generic .co.uk domains for sale
Important: All sale prices over 2 weeks old are automatically invalid. No exceptions.
Edwin is offline  
Old 04-12-2006, 09:22:14 PM     #8 (permalink)

 
olebean's Avatar
 
Join Date: Nov 2005
Location: Rarotonga
Posts: 2,272
olebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond repute

one of the most interesting parts is nobody wants to look at colleen!!
olebean is offline  
Old 05-12-2006, 09:17:42 AM     #9 (permalink)
Sedo Staff
 
sedo's Avatar
 
Join Date: Aug 2005
Location: High Holborn, London, UK
Posts: 913
sedo has a reputation beyond reputesedo has a reputation beyond reputesedo has a reputation beyond reputesedo has a reputation beyond reputesedo has a reputation beyond reputesedo has a reputation beyond reputesedo has a reputation beyond reputesedo has a reputation beyond reputesedo has a reputation beyond reputesedo has a reputation beyond reputesedo has a reputation beyond repute

Hi everyone,

Just had a talk with tech about this. As you are aware, if a session ID is posted anywhere and the user is online (meaning the session is still active), you will be logged into the other user's account.

Obviously, this is not desirable. We will be switching to Cookie sessions in the near future to do away with this problem, as we certainly want to make sure our system is as secure as possible.

Again, thank you for bringing this to our attention. Tech's working on the solution right now.

Kind regards,

Brad
brad.tilley@sedo.com
sedo is offline  
Closed Thread



Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off
Forum Jump

Similar Threads
Thread Thread Starter Domain Name Community Replies Last Post
sedo pro - how's your month going ?? pendragon Sedo 18 26-11-2006 10:32:14 PM

UK Cheapest


All times are GMT. The time now is 07:45:54 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.2
All content on Acorn Domains is member generated and is not moderated before posting. All content is viewed and used by you at your own risk and AD does not warrant the accuracy or reliability of any of the information. The views expressed are those of the individual contributors and not necessarily those of AD. Please contact us to report any issues or send a PM to "Admin".