Jump to content

Weird *albatross* security issue with Gunner website


swannie_2006

Recommended Posts

Hello all,

 

I am not sure if this should be in "general discussion" section but Gunner Airsoft doesn't have their own sub section in the retailer list so here it goes:

 

I have a strong feeling that the osCommerce engine they use to run their store on is "a bit" buggy. I was googling for some airsoft related products (namely pinion removal tool) when google threw a link at me on gunners.

I clicked onto the link and then, BAM! I was in some one else's account. I saw the guys past orders, his address book details, his email, phone number, birth date.. everything.

If I wanted, I could have changed his password without him knowing it or I could have ordered a bunch of *suitcase* in his name. Unfortunately I managed to wipe his shopping cart :P

 

Quickly, I sent him an email (based on his addresses a japanese guy living in the California,US) to change his password and double check his account and what not.

This is the second time I ended up in someone else's account (first one happened on Ebaybanned with their old engine) and both sites use/used osCommerce if I am not mistaken.

 

What can one do to avoid this? Not much, really. Even if you log off after each use if the google robot queries that website when you are logged in, chances are you are *fruitcage*ed. Either Gunner has to change their store engine or the engine supplier needs to rewrite it.

 

So, keep your eyes open, dudes and don't forget to log off every single time you used Gunners website.

 

 

 

 

Link to post
Share on other sites
Yep, Back in the day if you linked anything to gunners, Everyone could see your account and order details, ect. You need to make sure you log out before you link anything.

 

this is also the case with the new Zero one web page (http://www.zerooneairsoft.com/index.php), if you copy and paste the address from the address bar whilst logged in it does the exact same thing. Just be wary if your posting links to items anywhere.

Link to post
Share on other sites

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use and the use of session cookies.