To register for an Internet.com membership to receive newsletters and white papers, use the Register button ABOVE.
To participate in the message forums BELOW, click here


EIT Planet's Security News
 Security Vulnerabilities Prove Increasingly Costly
 IPS Market Approaches $1 Billion
 U.S. Named Top Spammer

Security Products
 Family Keylogger (Family Keylogger)
 modusGate (Vircom Inc.)
 Kernel Hotmail MSN Password Recovery (Nucleus Data Recovery)
 Outlook 2003 PST Password Recovery (PST Password Recovery)
 PST Password Remove (PST Password Remove)
 Zemana Anti Keylogger (Vickit, Inc.)


Go Back   Antionline Forums - Maximum Security for a Connected World > Security Discussions > Web Security

Web Security Security issues related to browsers, web site defacements, DOS, CGI, etc.

Reply
 
Thread Tools Display Modes
Old August 18th, 2009, 08:27 PM   #1
d34dl0k1
Member
 
d34dl0k1's Avatar
 
Join Date: Mar 2007
Posts: 56
d34dl0k1 is a glorious beacon of lightd34dl0k1 is a glorious beacon of lightd34dl0k1 is a glorious beacon of lightd34dl0k1 is a glorious beacon of lightd34dl0k1 is a glorious beacon of lightd34dl0k1 is a glorious beacon of light
tagged.com emails auto-login

I just signed up for tagged.com because I heard about something strange...

Apparently - they send email notifications with tokens in the URL that authenticate you automatically to their site after clicking...

I was wondering what kind of vulnerabilities would exist with this... For instance if my email account is ever used by anyone else again, they would receive these emails that let them into my account.

At the same time though, password reset emails would get them in all the same.

Does anyone else see this as a problem? It seems fishy...
d34dl0k1 is offline   Reply With Quote
Old August 18th, 2009, 09:45 PM   #2
SirDice
Just Another Geek
 
Join Date: Jul 2002
Location: Rotterdam, Netherlands
Posts: 3,329
SirDice has a reputation beyond reputeSirDice has a reputation beyond reputeSirDice has a reputation beyond reputeSirDice has a reputation beyond reputeSirDice has a reputation beyond reputeSirDice has a reputation beyond reputeSirDice has a reputation beyond reputeSirDice has a reputation beyond reputeSirDice has a reputation beyond reputeSirDice has a reputation beyond reputeSirDice has a reputation beyond repute
Quote:
Originally Posted by d34dl0k1 View Post
I just signed up for tagged.com because I heard about something strange...
Just a word to the wise, tagged doesn't have the best of reputations. Quite a lot of profiles are fake.

Quote:
Apparently - they send email notifications with tokens in the URL that authenticate you automatically to their site after clicking...
That's correct. They're not the only social network site that does this btw.

Quote:
I was wondering what kind of vulnerabilities would exist with this... For instance if my email account is ever used by anyone else again, they would receive these emails that let them into my account.
Correct. You also need to be careful when forwarding said emails. It will contain a link anyone can use to login on your account.

Quote:
Does anyone else see this as a problem? It seems fishy...
As I said, I've seen more sites do the exact same thing. Just be careful were you leave those emails.
__________________
Oliver's Law:
Experience is something you don't get until just after you need it.
SirDice is offline   Reply With Quote
Old August 19th, 2009, 11:42 AM   #3
nihil
Super Moderator: GMT Zone
 
nihil's Avatar
 
Join Date: Jul 2003
Location: United Kingdom: Bridlington
Posts: 15,901
nihil has a reputation beyond reputenihil has a reputation beyond reputenihil has a reputation beyond reputenihil has a reputation beyond reputenihil has a reputation beyond reputenihil has a reputation beyond reputenihil has a reputation beyond reputenihil has a reputation beyond reputenihil has a reputation beyond reputenihil has a reputation beyond reputenihil has a reputation beyond repute
You might find these links interesting?

http://www.consumerfraudreporting.or...ed_dot_com.php

http://foolswisdom.com/tagged-com-sp...ing-nice-guys/

http://spamnews.com/The-News/Latest/...2009073111567/

__________________
If you cannot do someone any good: don't do them any harm....
As long as you did this to one of these, the least of my little ones............you did it unto Me.

Last edited by nihil; August 19th, 2009 at 11:46 AM..
nihil is offline   Reply With Quote
Old August 19th, 2009, 12:40 PM   #4
t34b4g5
Moderator!™
 
t34b4g5's Avatar
 
Join Date: Sep 2003
Location: Australia.
Posts: 2,391
t34b4g5 has a reputation beyond reputet34b4g5 has a reputation beyond reputet34b4g5 has a reputation beyond reputet34b4g5 has a reputation beyond reputet34b4g5 has a reputation beyond reputet34b4g5 has a reputation beyond reputet34b4g5 has a reputation beyond reputet34b4g5 has a reputation beyond reputet34b4g5 has a reputation beyond reputet34b4g5 has a reputation beyond reputet34b4g5 has a reputation beyond repute
Darn somepeople have waaay to much time on there hands.

Reminds me of the 4 or so people suing FaceBook because they are to popular now.
t34b4g5 is offline   Reply With Quote
Old August 19th, 2009, 02:35 PM   #5
The-Spec
BANNΕD
 
The-Spec's Avatar
 
Join Date: Jan 2008
Posts: 433
The-Spec has a brilliant futureThe-Spec has a brilliant futureThe-Spec has a brilliant futureThe-Spec has a brilliant futureThe-Spec has a brilliant futureThe-Spec has a brilliant futureThe-Spec has a brilliant futureThe-Spec has a brilliant futureThe-Spec has a brilliant futureThe-Spec has a brilliant futureThe-Spec has a brilliant future
Quote:
One plaintiff is an 11-year-old boy who joined Facebook and then posted that he had swine flu and uploaded pictures or video of "partially-clothed" children swimming, according to the lawsuit.
Did people not catch the slight references to memes in that paragraph?

Edit: How much do you want to bet that the pool is closed due to swine flu?
__________________

Last edited by The-Spec; August 19th, 2009 at 06:13 PM..
The-Spec is offline   Reply With Quote
Old August 23rd, 2009, 04:15 AM   #6
PatrickDickey
Junior Member
 
Join Date: Aug 2009
Posts: 27
PatrickDickey is a jewel in the roughPatrickDickey is a jewel in the roughPatrickDickey is a jewel in the rough
Quote:
Originally Posted by The-Spec View Post
Did people not catch the slight references to memes in that paragraph?

Edit: How much do you want to bet that the pool is closed due to swine flu?
My gosh, they were "partially clothed" You mean their parents didn't make them wear those full-body bathing suits that were popular in the 1800's? What's this world coming too.......

Obviously the 11-year old's suit was written by his parents, or by a lawyer hoping to win on the anti-child-pornography wagon. Understand that I'm totally against child-porn as I have kids, but "partially clothed" at a swimming pool??? They need a life.

Have a great day
Patrick.
PatrickDickey is offline   Reply With Quote
Old August 23rd, 2009, 05:30 AM   #7
nihil
Super Moderator: GMT Zone
 
nihil's Avatar
 
Join Date: Jul 2003
Location: United Kingdom: Bridlington
Posts: 15,901
nihil has a reputation beyond reputenihil has a reputation beyond reputenihil has a reputation beyond reputenihil has a reputation beyond reputenihil has a reputation beyond reputenihil has a reputation beyond reputenihil has a reputation beyond reputenihil has a reputation beyond reputenihil has a reputation beyond reputenihil has a reputation beyond reputenihil has a reputation beyond repute
Hello Patrick,

Quote:
My gosh, they were "partially clothed"
ah! but it doesn't say which part?

Quote:
Obviously the 11-year old's suit was written by his parents
Who I would now have reported to the Social Welfare..........the parents let him run feral on the interwebz?

56 days in Colchester Military Corrective Training Centre............he will come out as something useful for Iraq/Afghanistan, or a vegetable
__________________
If you cannot do someone any good: don't do them any harm....
As long as you did this to one of these, the least of my little ones............you did it unto Me.
nihil is offline   Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Tracing Emails in Microsoft Outlook. FanacooL Computer Forensics 13 September 5th, 2006 09:46 AM
Secure Login System valhallen Programming Security 10 August 29th, 2006 10:46 PM
Tcp/ip gore Newbie Security Questions 11 December 29th, 2003 07:01 AM
auto login in RedHat Linux mani034 *nix Security Discussions 5 September 25th, 2003 01:19 PM
Newbies, list of many words definitions. -DaRK-RaiDeR- Newbie Security Questions 9 December 14th, 2002 07:38 PM


All times are GMT +1. The time now is 12:00 PM.












Acceptable Use Policy

Internet.com
The Network for Technology Professionals

Search:

About Internet.com

Legal Notices, Licensing, Permissions, Privacy Policy.
Advertise | Newsletters | E-mail Offers

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.