![]() |
| Domain Name Sales | Domain Software | Calculate UK Domain Drop Dates | Domain Lists | SedoPro Code | Domains For Sale | NameDrive | Domain Parking |
| |||||||
| Home | Register | Rules | Membership Upgrade | Featured Domains | Mark Forums Read | Domain Classified | Chat Room |
| Sedo Buying, Selling, Parking Domains with Sedo - Sign up for an account |
![]() |
| | Thread Tools | Display Modes |
| | #1 |
![]() | How's this for security I pressed a link to a sedo auction, and not only did it take me to the auction, it also logged me into the sellers account where I was free to browse his domains or do whatever I liked with his account. =Screenshot removed at the request of Sedo= Now that's what I call security ![]() Suppose posting the Session ID in the link didn't help Last edited by retired member 1; 05-12-2006 at 08:01:14 AM. |
| | |
| | #2 |
![]() | Jesus. discount the good uns and go buying...!! |
| | |
| | #3 |
![]() | Thanks for this info J2. I suppose the answer is to not let any domains go to Auction until Sedo confirm that this appalling glitch is sorted. |
| | |
| | #4 |
![]() Join Date: Jan 2005 Location: Edinburgh / Brisbane / Wales
Posts: 4,051
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Domain Trader Rating: (100% / 25) | I think it is if someone posts the URL themselves. I have had something similar when someone sent me a portfolio link - which had them still logged in! |
| | |
| | #5 |
![]() | Yes, seller posted Session ID with the link, session ID's don't last forever, don't suppose there is much Sedo can do about it, it's up to the person posting the link to make sure there is no Session ID in the link. |
| | |
| | #6 |
![]() | |
| | |
| | #7 |
![]() | You'd think a cookie test would be in order?
__________________ Memorable Domains: Over 2,500 generic .co.uk domains for sale |
| | |
| | #8 |
![]() | one of the most interesting parts is nobody wants to look at colleen!! |
| | |
| | #9 |
| Sedo Staff | Hi everyone, Just had a talk with tech about this. As you are aware, if a session ID is posted anywhere and the user is online (meaning the session is still active), you will be logged into the other user's account. Obviously, this is not desirable. We will be switching to Cookie sessions in the near future to do away with this problem, as we certainly want to make sure our system is as secure as possible. Again, thank you for bringing this to our attention. Tech's working on the solution right now. Kind regards, Brad brad.tilley@sedo.com |
| | |
![]() |
| Bookmarks |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads | ||||
| Thread | Thread Starter | Domain Name Community | Replies | Last Post |
| sedo pro - how's your month going ?? | pendragon | Sedo | 18 | 26-11-2006 09:32:14 PM |