Buy Sell Discuss UK Domain Names at AcornDomains.co.uk Domain Sponsor

Today's drop dates are 25-08-2008 & 01-09-2008  
Domain Name Sales Domain Software Calculate UK Domain Drop Dates Domain Lists SedoPro Code Domains For Sale NameDrive Domain Parking
Go Back   Domain Name Forum Acorn Domains Buy Sell Trade UK Domain Names > Domain Parking > Sedo

Sedo Buying, Selling, Parking Domains with Sedo - Sign up for an account

Reply
 
Thread Tools Display Modes
Old 04-12-2006, 04:45 PM   #1

 
Join Date: Apr 2005
Posts: 759
retired member 1 has a reputation beyond reputeretired member 1 has a reputation beyond reputeretired member 1 has a reputation beyond reputeretired member 1 has a reputation beyond reputeretired member 1 has a reputation beyond reputeretired member 1 has a reputation beyond reputeretired member 1 has a reputation beyond reputeretired member 1 has a reputation beyond reputeretired member 1 has a reputation beyond reputeretired member 1 has a reputation beyond reputeretired member 1 has a reputation beyond repute

How's this for security

I pressed a link to a sedo auction, and not only did it take me to the auction, it also logged me into the sellers account where I was free to browse his domains or do whatever I liked with his account.

=Screenshot removed at the request of Sedo=

Now that's what I call security

Suppose posting the Session ID in the link didn't help

Last edited by retired member 1; 05-12-2006 at 10:01 AM.
retired member 1 is offline   Reply With Quote
Old 04-12-2006, 05:09 PM   #2

 
ratboy's Avatar
 
Join Date: Sep 2005
Posts: 1,381
ratboy has a reputation beyond reputeratboy has a reputation beyond reputeratboy has a reputation beyond reputeratboy has a reputation beyond reputeratboy has a reputation beyond reputeratboy has a reputation beyond reputeratboy has a reputation beyond reputeratboy has a reputation beyond reputeratboy has a reputation beyond reputeratboy has a reputation beyond reputeratboy has a reputation beyond repute

Jesus. discount the good uns and go buying...!!
ratboy is offline   Reply With Quote
Old 04-12-2006, 05:15 PM   #3

 
Join Date: May 2005
Posts: 384
Nigel has a reputation beyond reputeNigel has a reputation beyond reputeNigel has a reputation beyond reputeNigel has a reputation beyond reputeNigel has a reputation beyond reputeNigel has a reputation beyond reputeNigel has a reputation beyond reputeNigel has a reputation beyond reputeNigel has a reputation beyond reputeNigel has a reputation beyond reputeNigel has a reputation beyond repute

Thanks for this info J2. I suppose the answer is to not let any domains go to Auction until Sedo confirm that this appalling glitch is sorted.
Nigel is offline   Reply With Quote
Old 04-12-2006, 05:18 PM   #4
rob

 
rob's Avatar
 
Join Date: Jan 2005
Location: Edinburgh / Brisbane / Wales
Posts: 3,180
rob has a reputation beyond reputerob has a reputation beyond reputerob has a reputation beyond reputerob has a reputation beyond reputerob has a reputation beyond reputerob has a reputation beyond reputerob has a reputation beyond reputerob has a reputation beyond reputerob has a reputation beyond reputerob has a reputation beyond reputerob has a reputation beyond repute

I think it is if someone posts the URL themselves.

I have had something similar when someone sent me a portfolio link - which had them still logged in!
rob is offline   Reply With Quote
Old 04-12-2006, 05:46 PM   #5

 
Join Date: Apr 2005
Posts: 759
retired member 1 has a reputation beyond reputeretired member 1 has a reputation beyond reputeretired member 1 has a reputation beyond reputeretired member 1 has a reputation beyond reputeretired member 1 has a reputation beyond reputeretired member 1 has a reputation beyond reputeretired member 1 has a reputation beyond reputeretired member 1 has a reputation beyond reputeretired member 1 has a reputation beyond reputeretired member 1 has a reputation beyond reputeretired member 1 has a reputation beyond repute

Yes, seller posted Session ID with the link, session ID's don't last forever, don't suppose there is much Sedo can do about it, it's up to the person posting the link to make sure there is no Session ID in the link.
retired member 1 is offline   Reply With Quote
Old 04-12-2006, 06:23 PM   #6

 
olebean's Avatar
 
Join Date: Nov 2005
Location: Rarotonga
Posts: 2,252
olebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond repute

unbelievable
olebean is offline   Reply With Quote
Old 04-12-2006, 10:18 PM   #7

 
Join Date: Apr 2005
Location: Tokyo, Japan
Posts: 910
Edwin has a reputation beyond reputeEdwin has a reputation beyond reputeEdwin has a reputation beyond reputeEdwin has a reputation beyond reputeEdwin has a reputation beyond reputeEdwin has a reputation beyond reputeEdwin has a reputation beyond reputeEdwin has a reputation beyond reputeEdwin has a reputation beyond reputeEdwin has a reputation beyond reputeEdwin has a reputation beyond repute

You'd think a cookie test would be in order?
Edwin is offline   Reply With Quote
Old 04-12-2006, 10:22 PM   #8

 
olebean's Avatar
 
Join Date: Nov 2005
Location: Rarotonga
Posts: 2,252
olebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond repute

one of the most interesting parts is nobody wants to look at colleen!!
__________________
[SIZE="2"]Selling: CasinoPlaying Wedding AgencyJobs and: ToLet DomainsDirectory Property
Wedding
[/SIZE]
olebean is offline   Reply With Quote
Old 05-12-2006, 10:17 AM   #9
Sedo Staff
 
sedo's Avatar
 
Join Date: Aug 2005
Location: High Holborn, London, UK
Posts: 722
sedo has a reputation beyond reputesedo has a reputation beyond reputesedo has a reputation beyond reputesedo has a reputation beyond reputesedo has a reputation beyond reputesedo has a reputation beyond reputesedo has a reputation beyond reputesedo has a reputation beyond reputesedo has a reputation beyond reputesedo has a reputation beyond reputesedo has a reputation beyond repute

Hi everyone,

Just had a talk with tech about this. As you are aware, if a session ID is posted anywhere and the user is online (meaning the session is still active), you will be logged into the other user's account.

Obviously, this is not desirable. We will be switching to Cookie sessions in the near future to do away with this problem, as we certainly want to make sure our system is as secure as possible.

Again, thank you for bringing this to our attention. Tech's working on the solution right now.

Kind regards,

Brad
brad.tilley@sedo.com
sedo is offline   Reply With Quote
Reply



Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off
Forum Jump

Similar Threads
Thread Thread Starter Domain Name Community Replies Last Post
sedo pro - how's your month going ?? pendragon Sedo 18 26-11-2006 11:32 PM


All times are GMT +1. The time now is 03:47 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86