logo

Debtconsolidationcare.com - the USA consumer forum

MAJOR PROGRAMMING ERROR with DCC

Date: Mon, 05/12/2008 - 07:39

Submitted by goudah2424
on Mon, 05/12/2008 - 07:39

Posts: 7935 Credits: [Donate]

Total Replies: 42


FYI to Admin - There is a major programming error on this site that makes it INCREDIBLY simple to break into any users account here . . . . Anybody that thought about it could figure it out, and it requires no skill at all.

I'm not going to post how to do it, but it's really easy. It's a serious shortfall in the programming here, and should be fixed immediatly, which is why I'm posting here instead of just pming, because I figure that would just be ignored.

Admin can contact me and I'll explain to them the weakness . . . . . I haven't actually tried it myself because I wouldn't want to, but I'm 100% sure it would work.


No . . . . . I was just laying in bed the other night and I realized that it's totally simple because of the way things are set up here . . . .

Pretty much, with a couple clicks of the mouse, anyone could break into any member's account here and read their pm's, post as them, use their MOD or Admin powers, etc . . . . It's really simple, and you wouldn't need much, if any, computer knowledge to do it.


lrhall41

Submitted by goudah2424 on Mon, 05/12/2008 - 08:51

( Posts: 7935 | Credits: )


I don't get it either . . . . Either they just think I don't know what I'm talking about, or don't believe me, or think their system is foolproof.

You don't have to be a hacker. You don't have to have any programming knowledge. It's simple. One of these days someone else will figure it out with not so good intentions and lots of people will be upset.


lrhall41

Submitted by goudah2424 on Tue, 05/13/2008 - 08:31

( Posts: 7935 | Credits: )


Goudah - thank you for pointing this issue out. It's definitely a major concern, and I hope Admin can find time to address it soon! I saw that Jason was on here briefly and answered one question about someone posting a blog...but I don't see that any of the issues in the Mod forum have been addressed.

I understand that they are shorthanded and very busy right now, but I sure would like some sort of explanation as to why important issues are not being addressed, or posts answered.

Does anyone know if the points redemption issue has been addressed, as to when payments are sent?


lrhall41

Submitted by SUEBEEHONEY70 on Fri, 05/16/2008 - 10:01

( Posts: 4583 | Credits: )


I'm willing to give them the benefit of the doubt. Maybe they ARE working on it. Maybe they already have, has anyone tried to find out?

Maybe there is other stuff going on that we don't know about. I guess I don't really care if anyone can break into my "account" or not..What harm can they really do? It's not like I have an overwhelming amount of personal info here..If they get my email addy, oh well..I can block that. And if someone wants to read my pms, let them. And..If someone wants to attempt to post as me..I think that would be just great. I've been here for more than 2 years. The people who matter know my posting style, and anyway, ip addies can prove it's not me. I'm just going to cut everyone some slack and not concern myself. I'll be ok.


lrhall41

Submitted by finsfan13 on Sat, 05/17/2008 - 12:29

( Posts: 6919 | Credits: )


When I was in grade school, I was able to get into the school's network and read memos and such. ... In high school I was able to manipulate the attendance records and change my friends grades. ... In college I once hacked into a hotel's network and saw all their guests bills and credit card numbers. ...

Funny that with a bachelor's degree in network technology, I can't manage to hack into this site.

Must be something so completely easy that it's just going right past me. Ah well, like Fins said, the worst someone will get is my email -- which I use a disposable email here anyway.


lrhall41

Submitted by DebtCruncher on Sat, 05/17/2008 - 20:30

( Posts: 2293 | Credits: )


Someone already hacked into mine a couple of months back--erased the nasty qms and pms they wrote--never did figure out that one :lol:

I thought I knew how they did it, but after thinking about it, I don't--am computer stupid and don't have the time to think about it or worry, I don't put in personal info in any of them anyhow..


lrhall41

Submitted by Bossy4455 on Sun, 05/18/2008 - 09:05

( Posts: 5854 | Credits: )


I played around with the password reset a little. I found that the re-activation link sent via email passed my UID as a parameter (along with a token and and a mode as arguments). I suspected that I might be able to manipulate a password reset by inserting someone else's UID into the re-activation link. However the token it passes, as well as the new temporary password, are both randomly generated Hexidecimal strings. Without knowing the token, the system would not let me go further. I therefore was unsuccessful in that front, since it would still be a matter of guesswork to guess a token with 16777216 possible combinations.


lrhall41

Submitted by DebtCruncher on Sun, 05/18/2008 - 18:28

( Posts: 2293 | Credits: )


Can it be so simple that you're referring to the fact that everyone's default password is 9, when they set up a new account, until they change it ???

Any user who's never taken the time to change their password, we already know it is 9. Getting their email from their profile, any user would be able to login as them.

That is, until they ever change their default password, which the system warns them to do in the first place ...


lrhall41

Submitted by DebtCruncher on Sun, 05/18/2008 - 18:37

( Posts: 2293 | Credits: )


Hi, its not that I'm not around or I have no wind of this thread. I'm here :D and have already spoken to the techies about this issue and also breathing on their neck to get it solved, :wink: though according to them the chances are nearly remote. If anyone of you have faced this problem of late , please report it to me, because it would be easier for me to talk to them if I've an example to show.

The reason I haven't replied to this thread or hadn't spoken to goudah yet, because I'm too am a mere illiterate as anyone else with the technologies :oops:

Regards,
Jason


lrhall41

Submitted by Jason on Sun, 05/18/2008 - 21:40

( Posts: 2430 | Credits: )


Hey, if its the password you're talking about, you can always reset it by going to the edit profile option after login in. And its advisable to do after you're signing-in. This way your information will stay protected.

When you sign in with debtcc, it allots you the default password 9, but you can always change it by going to the edit profile option.

Goudah, I guess I've solved your problem :D if not then pls drop me a PM with the details, because anything more technical is beyond my capacity.

However, all the data of the members are stored in an encrypted form, which is not easy to decipher. Please be assured that all your information are secured :D

Regards,
Jason


lrhall41

Submitted by Jason on Mon, 05/19/2008 - 20:34

( Posts: 2430 | Credits: )


Hi,

If you try to retrieve your password by putting your e-mail id the system generates a random password and doesn't reset it at the default one.

Quote:

I tried it last week with my own account and it reset to 9 each time.


May be the system has picked the default password randomly each time. But I think it doesn't happen in a regular basis.

the default password is assigned to you only at the time your register with debtcc. However, its advisable to change it just after you login-in with your account.

As I have mentioned earlier, the data get stored in an encrypted form at the database, and hence, secured.

Regards,
Jason


lrhall41

Submitted by Jason on Thu, 05/22/2008 - 04:52

( Posts: 2430 | Credits: )