Buy Sell Discuss UK Domain Names at AcornDomains.co.uk Domain Sponsor

Today's drop dates are 25-08-2008 & 01-09-2008  
Domain Name Sales Domain Software Calculate UK Domain Drop Dates Domain Lists SedoPro Code Domains For Sale NameDrive Domain Parking
Go Back   Domain Name Forum Acorn Domains Buy Sell Trade UK Domain Names > Domain Parking > Sedo

Sedo Buying, Selling, Parking Domains with Sedo - Sign up for an account

Reply
 
Thread Tools Display Modes
Old 29-08-2007, 07:32 PM   #21

 
olebean's Avatar
 
Join Date: Nov 2005
Location: Rarotonga
Posts: 2,252
olebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond repute

PM sent to Sedo!
olebean is offline   Reply With Quote
Old 29-08-2007, 09:12 PM   #22

 
rjs_essex's Avatar
 
Join Date: Oct 2006
Location: Essex
Posts: 1,450
rjs_essex has a reputation beyond reputerjs_essex has a reputation beyond reputerjs_essex has a reputation beyond reputerjs_essex has a reputation beyond reputerjs_essex has a reputation beyond reputerjs_essex has a reputation beyond reputerjs_essex has a reputation beyond reputerjs_essex has a reputation beyond reputerjs_essex has a reputation beyond reputerjs_essex has a reputation beyond reputerjs_essex has a reputation beyond repute

This has always been a serious security flaw with Sedo's login system. It creates session urls that don't expire from one user / machine to another... Hence why you should never put sedo links anywhere on the net that include your session data within the url!

Lee - I have edited your original post for you - I hope anyone reading this thread (even guests) have not done anything untoward - Double check your account settings etc!

Rich
__________________
Richard | Atomic Edge | Phone Insurance
rjs_essex is offline   Reply With Quote
Old 29-08-2007, 09:24 PM   #23

 
olebean's Avatar
 
Join Date: Nov 2005
Location: Rarotonga
Posts: 2,252
olebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond reputeolebean has a reputation beyond repute

Quote:
Originally Posted by rjs_essex View Post
This has always been a serious security flaw with Sedo's login system. It creates session urls that don't expire from one user / machine to another... Hence why you should never put sedo links anywhere on the net that include your session data within the url!

Lee - I have edited your original post for you - I hope anyone reading this thread (even guests) have not done anything untoward - Double check your account settings etc!

Rich
And change passwords!!
olebean is offline   Reply With Quote
Old 29-08-2007, 09:52 PM   #24

 
rjs_essex's Avatar
 
Join Date: Oct 2006
Location: Essex
Posts: 1,450
rjs_essex has a reputation beyond reputerjs_essex has a reputation beyond reputerjs_essex has a reputation beyond reputerjs_essex has a reputation beyond reputerjs_essex has a reputation beyond reputerjs_essex has a reputation beyond reputerjs_essex has a reputation beyond reputerjs_essex has a reputation beyond reputerjs_essex has a reputation beyond reputerjs_essex has a reputation beyond reputerjs_essex has a reputation beyond repute

Quote:
Originally Posted by olebean View Post
And change passwords!!
Always a good idea but at Sedo you can't see you current password and you have to enter your old password to create a new one so no one could have changed it and even if they did you would be unable to log back in...
__________________
Richard | Atomic Edge | Phone Insurance
rjs_essex is offline   Reply With Quote
Old 30-08-2007, 08:11 AM   #25
Sedo Staff
 
sedo's Avatar
 
Join Date: Aug 2005
Location: High Holborn, London, UK
Posts: 722
sedo has a reputation beyond reputesedo has a reputation beyond reputesedo has a reputation beyond reputesedo has a reputation beyond reputesedo has a reputation beyond reputesedo has a reputation beyond reputesedo has a reputation beyond reputesedo has a reputation beyond reputesedo has a reputation beyond reputesedo has a reputation beyond reputesedo has a reputation beyond repute

Hi Everybody,

Thank you all for this, I'll get our tech-people on this straight away.

Shaun
sedo is offline   Reply With Quote
Old 30-08-2007, 10:18 AM   #26
Sedo Staff
 
sedo's Avatar
 
Join Date: Aug 2005
Location: High Holborn, London, UK
Posts: 722
sedo has a reputation beyond reputesedo has a reputation beyond reputesedo has a reputation beyond reputesedo has a reputation beyond reputesedo has a reputation beyond reputesedo has a reputation beyond reputesedo has a reputation beyond reputesedo has a reputation beyond reputesedo has a reputation beyond reputesedo has a reputation beyond reputesedo has a reputation beyond repute

Hello All,

A message from Sedo's technical department, although one I'm sure most of you are aware of this - never post links containing session ID's!! It is written in our terms and conditions, and also in our FAQ's, that this should never be done. Our techies are currently working on a solution to this, hopefully making it impossible to get into accounts this way even if the links are posted.

However, please take care with this!

Regards,

Shaun

shaun.wilkinson@sedo.com
sedo is offline   Reply With Quote
Old 30-08-2007, 11:56 AM   #27

 
rjs_essex's Avatar
 
Join Date: Oct 2006
Location: Essex
Posts: 1,450
rjs_essex has a reputation beyond reputerjs_essex has a reputation beyond reputerjs_essex has a reputation beyond reputerjs_essex has a reputation beyond reputerjs_essex has a reputation beyond reputerjs_essex has a reputation beyond reputerjs_essex has a reputation beyond reputerjs_essex has a reputation beyond reputerjs_essex has a reputation beyond reputerjs_essex has a reputation beyond reputerjs_essex has a reputation beyond repute

Quote:
Originally Posted by sedo View Post
Hello All,

A message from Sedo's technical department, although one I'm sure most of you are aware of this - never post links containing session ID's!! It is written in our terms and conditions, and also in our FAQ's, that this should never be done. Our techies are currently working on a solution to this, hopefully making it impossible to get into accounts this way even if the links are posted.

However, please take care with this!

Regards,

Shaun

shaun.wilkinson@sedo.com
How long have they been working on this? It's been the same since I can remember... Sedo is the only major site that I know of that has this problem... its very lax security in my opinion...
__________________
Richard | Atomic Edge | Phone Insurance
rjs_essex is offline   Reply With Quote
Old 30-08-2007, 03:12 PM   #28
Sedo Staff
 
sedo's Avatar
 
Join Date: Aug 2005
Location: High Holborn, London, UK
Posts: 722
sedo has a reputation beyond reputesedo has a reputation beyond reputesedo has a reputation beyond reputesedo has a reputation beyond reputesedo has a reputation beyond reputesedo has a reputation beyond reputesedo has a reputation beyond reputesedo has a reputation beyond reputesedo has a reputation beyond reputesedo has a reputation beyond reputesedo has a reputation beyond repute

My colleague in the tech department that system updates to resolve this problem should be up and running within a couple of weeks.

Regards,

Shaun

shaun.wilkinson@sedo.com
sedo is offline   Reply With Quote
Old 30-08-2007, 03:32 PM   #29

 
aquanuke's Avatar
 
Join Date: May 2005
Posts: 1,804
aquanuke has a reputation beyond reputeaquanuke has a reputation beyond reputeaquanuke has a reputation beyond reputeaquanuke has a reputation beyond reputeaquanuke has a reputation beyond reputeaquanuke has a reputation beyond reputeaquanuke has a reputation beyond reputeaquanuke has a reputation beyond reputeaquanuke has a reputation beyond reputeaquanuke has a reputation beyond reputeaquanuke has a reputation beyond repute

Quote:
Originally Posted by sedo View Post
My colleague in the tech department that system updates to resolve this problem should be up and running within a couple of weeks.

Regards,

Shaun

shaun.wilkinson@sedo.com
How's this for security

Couple of weeks, Almost a year since last time someone mentioned this problem.
aquanuke is offline   Reply With Quote
Old 31-08-2007, 03:47 AM   #30
Banned
 
LeeOwen's Avatar
 
Join Date: Apr 2005
Location: Dristor, Bucharest, Romania
Posts: 3,713
LeeOwen has a reputation beyond reputeLeeOwen has a reputation beyond reputeLeeOwen has a reputation beyond reputeLeeOwen has a reputation beyond reputeLeeOwen has a reputation beyond reputeLeeOwen has a reputation beyond reputeLeeOwen has a reputation beyond reputeLeeOwen has a reputation beyond reputeLeeOwen has a reputation beyond reputeLeeOwen has a reputation beyond reputeLeeOwen has a reputation beyond repute

Quote:
Originally Posted by sedo View Post
Hello All,

A message from Sedo's technical department, although one I'm sure most of you are aware of this - never post links containing session ID's!! It is written in our terms and conditions, and also in our FAQ's, that this should never be done. Our techies are currently working on a solution to this, hopefully making it impossible to get into accounts this way even if the links are posted.

However, please take care with this!

Regards,

Shaun

shaun.wilkinson@sedo.com
so sue me, take care of your own security.
LeeOwen is offline   Reply With Quote
Reply



Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off
Forum Jump

Similar Threads
Thread Thread Starter Domain Name Community Replies Last Post
2/3/4 page site required to be made! lex007 Website Design 1 26-09-2006 04:13 PM
Taking Offers LeeOwen Top Level Domain Names For Sale 0 20-09-2006 12:18 PM
Under £100 Meltdown Archive UK Domains For Sale 1 02-05-2006 10:58 PM
Link to a certain section of a page? How to? BFTUK Website Design 2 14-02-2006 01:33 PM


All times are GMT +1. The time now is 05:01 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86