Membership is FREE – with unlimited access to all features, tools, and discussions. Premium accounts get benefits like banner ads and newsletter exposure. ✅ Signature links are now free for all. 🚫 No AI-generated (LLM) posts allowed. Share your own thoughts and experience — accounts may be terminated for violations.

How's this for security

Status
Not open for further replies.
Joined
Apr 15, 2005
Posts
634
Reaction score
14
I pressed a link to a sedo auction, and not only did it take me to the auction, it also logged me into the sellers account where I was free to browse his domains or do whatever I liked with his account.

=Screenshot removed at the request of Sedo=

Now that's what I call security :rolleyes:

Suppose posting the Session ID in the link didn't help :D
 
Last edited:
I think it is if someone posts the URL themselves.

I have had something similar when someone sent me a portfolio link - which had them still logged in!
 
Yes, seller posted Session ID with the link, session ID's don't last forever, don't suppose there is much Sedo can do about it, it's up to the person posting the link to make sure there is no Session ID in the link.
 
one of the most interesting parts is nobody wants to look at colleen!!
 
Hi everyone,

Just had a talk with tech about this. As you are aware, if a session ID is posted anywhere and the user is online (meaning the session is still active), you will be logged into the other user's account.

Obviously, this is not desirable. We will be switching to Cookie sessions in the near future to do away with this problem, as we certainly want to make sure our system is as secure as possible.

Again, thank you for bringing this to our attention. Tech's working on the solution right now.

Kind regards,

Brad
[email protected]
 
Status
Not open for further replies.

Rule #1: Be Respectful

Do not insult any other member. Be polite and do business. Thank you!

Premium Members

New Threads

Domain Forum Friends

Lastest Listings

Our Mods' Businesses

*the exceptional businesses of our esteemed moderators
General chit-chat
Help Users
  • No one is chatting at the moment.
  • Siusaidh AcornBot:
    Siusaidh has left the room.
      Siusaidh AcornBot: Siusaidh has left the room.
      Top Bottom