Mon, Sep 9, 7:39 AM CDT

Renderosity Forums / Bryce



Welcome to the Bryce Forum

Forum Moderators: TheBryster

Bryce F.A.Q (Last Updated: 2024 Aug 28 6:28 pm)

[Gallery]     [Tutorials]


THE PLACE FOR ALL THINGS BRYCE - GOT A PROBLEM? YOU'VE COME TO THE RIGHT PLACE


Subject: Security???


DJB ( ) posted Tue, 20 April 2004 at 11:55 PM · edited Sun, 08 September 2024 at 6:46 AM

Did you know that if you paste a link to a friend and you are logged in at the time when they click the link,they log in under your ID. This happened earlier tonight...And, has happened before.
So I tried something...I logged out,then typed search by artist on their name, but before I even typed their name I was logged into thier ID ...(while they were logged into their name).This was all simutaenously done.
So wierd???

"The happiness of a man in this life does not consist in the absence but in the mastery of his passions."



AgentSmith ( ) posted Wed, 21 April 2004 at 12:27 AM

Yes. Always be VERY careful when you copy paste links. NEVER include in a link your ID info. (anything that looks like this at the end of a Renderosity URL); &Form.sess_id=4452288&Form.sess_key=218477351 Or, you can end up doing exactly what you described. And, I know its a pain, but you should ALWAYS log out/log in, not just close the browser window. AgentSmith

Contact Me | Gallery | Freestuff | IMDB Credits | Personal Site
"I want to be what I was when I wanted to be what I am now"


DJB ( ) posted Wed, 21 April 2004 at 1:20 AM

I know that now,and I do get lazy about just shutting the browser off. No more though.

"The happiness of a man in this life does not consist in the absence but in the mastery of his passions."



AgentSmith ( ) posted Wed, 21 April 2004 at 1:32 AM

One small good thing, if anyone were to accomplish this, they could usually only load up a handful of pages before it wouldn't work anymore. AS

Contact Me | Gallery | Freestuff | IMDB Credits | Personal Site
"I want to be what I was when I wanted to be what I am now"


DJB ( ) posted Wed, 21 April 2004 at 1:43 AM

But really it's not like there is any big secrets here .So can't worry about it.Anything on the internet is avail to the public .Just a matter of how bad one wants something. Locks are only for the innocent.

"The happiness of a man in this life does not consist in the absence but in the mastery of his passions."



gillbrooks ( ) posted Wed, 21 April 2004 at 3:30 AM

I pasted a link to a DAZ item to a friend while chatting on AIM last week - she used that link to look at the item, then added it to her cart - or so she thought. Turns out she'd added it to MY cart!!

Gill

       


pogmahone ( ) posted Wed, 21 April 2004 at 4:01 AM

........or I suppose you could mess with someone's gallery? Post nudey pics or whatever.


Rochr ( ) posted Wed, 21 April 2004 at 5:09 AM

...delete everything...

Rudolf Herczog
Digital Artist
www.rochr.com


Erlik ( ) posted Wed, 21 April 2004 at 7:15 AM

... get them banned ... Scary.

-- erlik


DJB ( ) posted Wed, 21 April 2004 at 9:42 AM

Quote: I pasted a link to a DAZ item to a friend while chatting on AIM last week - she used that link to look at the item, then added it to her cart - or so she thought. Turns out she'd added it to MY cart!! Did'nt she notice that the page layout colors were different? Unless her Renderosity setup is the same as yours. LOL That's how we figured it out right away.

"The happiness of a man in this life does not consist in the absence but in the mastery of his passions."



draculaz ( ) posted Wed, 21 April 2004 at 9:53 AM

okay, this is a security hole the size of texas. i had no idea about it. and i'm sorry, but it's horrible... sessionkeys should be cookie-based, not user-based... i'm shocked. drac


gillbrooks ( ) posted Wed, 21 April 2004 at 11:23 AM

dBgrafix : It was a DAZ link, not Renderosity, although probably wouldn't notice here either - I just leave the default page setup ;-)

Gill

       


ddruckenmiller ( ) posted Wed, 21 April 2004 at 12:00 PM

Echo Drac. Within the current legal climate there are certain liability and regulatory issues. California Civil Codes 1798.29 and 1798.82 jump to mind. (also collectively referred to as SB1386) These apply irrespective of where the information and business is actually homed - and apply to entities doing business with CA based merchants or residents. Thank a poor security implementation A Guess for that...


Damia ( ) posted Wed, 21 April 2004 at 6:45 PM

I didn't know that happened. That is really awful. I don't usually post links to my gallery since it is almost non-existent, but still. I realize people can get into stuff if they really tried, but it shouldn't be this easy.

~Damia~ LeviathanPhotography


TheBryster ( ) posted Wed, 21 April 2004 at 9:11 PM
Forum Moderator

...So I could pretend to be...er....Drac....for example? HEHEHEH!

Available on Amazon for the Kindle E-Reader

All the Woes of a World by Jonathan Icknield aka The Bryster


And in my final hours - I would cling rather to the tattooed hand of kindness - than the unblemished hand of hate...


Privacy Notice

This site uses cookies to deliver the best experience. Our own cookies make user accounts and other features possible. Third-party cookies are used to display relevant ads and to analyze how Renderosity is used. By using our site, you acknowledge that you have read and understood our Terms of Service, including our Cookie Policy and our Privacy Policy.