Security Issue - wrong user login after while or immediately

Dimitris Kerestetzis Posted in Beginning Developers 10 years ago

Hello,

Some users in my ossn platform make login and after while change their user profile!

For example... John Smith make login and after while or immediately change his profile to an other user in my ossn platform e.g. George Foo.

How can I check or what is maybe the problem here?

Thank you,
Dimitris

Replies
German Michael Zülsdorff Replied 10 years ago

I'm sorry, but we're unable to investigate your issue.

Your site is that highly customized, starting with a completely different user registration, account handling/verification and numerous 3rd party javascripts, that all kind of unexpected things may happen.

All I can recommend is:

  • Consult the responsible programmer(s).

and/or

  • Remove all custom stuff
  • update to the latest Ossn
  • and add those custom parts step by step until the problem pops up again.
gr Dimitris Kerestetzis Replied 10 years ago

"If I had an acount in your community, visiting my profile would lead me to the page YOURCOMMUNITY.COM/u/zetman
What exactly does happen then? Does the page refresh automativally and I'm led to YOURCOMMUNITY.COM/u/dimitris instead?"

Dear ZET MAN, This is exactly what is happening.

The site is deepmind.gr

Thank you for your help.

German Michael Zülsdorff Replied 10 years ago

Hmm ... let me try to understand...
If I had an acount in your community, visiting my profile would lead me to the page YOURCOMMUNITY.COM/u/zetman

What exactly does happen then? Does the page refresh automativally and I'm led to YOURCOMMUNITY.COM/u/dimitris instead?

Maybe you can give me your site name and I'm trying myself

gr Dimitris Kerestetzis Replied 10 years ago

Dear Zet Man: we don't have a problem with similar names. The problem that we have is when we are in our profile, the next moment we see the profile of an other person and we can change his settings!!

This issue happens several times in the last hours to us and many other users.

Please advise.

German Michael Zülsdorff Replied 10 years ago

Actually, Ossn users cannot take over other user's profiles, because every user profile is hardwired to the username which gets verified to be unique. Thus: NO security issue.

What people may do is changing the Firstname and the Lastname, that's right. But it makes no sense to make Ossn check for duplicates here, because there's a good chance that there are in fact two or more John Smiths in this world.

The sad truth is that with almost every community you'll sooner or later see this sort of childish idiots arrive, and all you can do is making use of your admin power and warn, ban or delete them.

Premium Version

Due to the many requests in the past for additonal features and components we have decided to develope a premium version. Features like Hashtags, Videos, Polls, Events, Stories, Link Preview, etc included in it.

$199 (Life Time)
Learn More

Other Questions