Forum: MarketPlace Customers


Subject: Fix This!!

-Wolfie- opened this issue on Mar 13, 2006 · 8 posts


-Wolfie- posted Mon, 13 March 2006 at 8:39 PM

I don't know which forum to post this to, so I am hoping regardless this issue can be taken care of. Thankfully, this is something that happened between a few friends of mine... One shared a link to a new gallery image she posted, and the URL contained her SESSION ID, so when we all visited her gallery image we were logged in as her. She logged out, and when we clicked the link again, it logged us in as one of the other ladies, and so on until it logged us in as nearly all of us. Now this has been going on for some time. I have even brought this issue up before. And with the new upgrade you would think the programmers would have fixed this nonsense. Some of my friends are part of a few Poser groups where they share their progress by sending in links to their gallery images... and because the session ID PROBLEM she unwillingly gave access to her account to members of her Poser group. Now you can say that the programmers will look into it.. but will it be another FIVE years before it gets fixed?! When someone has access to our accounts, by NO FAULT of our own, we cannot be help accountable for what they do. i.e stealing out items. Why then is it so tabu to share poser stuff, yet RO is refusing to correct this issue??? Is it not the same thing?? Dammit all! FIX IT! ~Wolfie~

Helping everyone is the most rewarding failure you'll ever experience.
    - Ray Augé (~Wolfie~'s hubby)

Anything is more stable than Windows . . .
--- Even a relationship based purely on sex!

    - Pam Augé (~Wolfie~)

No meat was harmed during the making of this TV dinner.
    - Pam Augé (~Wolfie~)



hevensblueyes posted Mon, 13 March 2006 at 8:44 PM

I have to agree with ~Wolfie~'s Post This has happened to me as well and Frankly I am sick of it as well. SO we do spend our hard earned money to purchase things from RO for what ? to share a gallery image and have some one steal our purchased Items.. Now is that highway robbery or what ? You know why do I bother even sending a link to show friends and family when they can just log in as me with that Link. be so kind and fix this problem like this life time. I just won't purchase from RO in this life time ever again if it doesn't get resolved. hey the other people who get my link get a 5 finger discount on the behalf of me and it wasn't even my fault!


Lil.BizE posted Mon, 13 March 2006 at 8:46 PM

I hear ya wolfie,, i too would like this fixed, it has happened to me on a few occasions, and would think it would have been fixed right away. Basically, anybody can hack into my account, just by clicking a link to a gallery image! This is a serious issue, and needs to be considered as such.


StaceyG posted Mon, 13 March 2006 at 8:53 PM

Hi, I know this is frustrating but it will be resolved with the conversion to the PHP platform because we will be requiring RR cookies accepted as we do on the Marketplace now. As for now, the session ID times out after I think its 15 minutes (don't quote me on the exact time but I believe that is it) and anytime a URL is sent to anyone, you must always be sure to take out any session ID's out of the URL. The Community conversion is in the works now with the forums going first, then the galleries. I don't have an exact date on when this will be completed but please understand that it is a very timely process and the programmers are working hard daily. Once again until the conversion is complete, please be sure and don't send URL's with session Id's in them. Thanks Stacey Community Manager


-Wolfie- posted Mon, 13 March 2006 at 9:33 PM

Oh that is great news!! YAY I knew I loved PHP for a reason.. other than what I designed my site with. LOL! Thanks for the heads up Stacey! ~Wolfie~

Helping everyone is the most rewarding failure you'll ever experience.
    - Ray Augé (~Wolfie~'s hubby)

Anything is more stable than Windows . . .
--- Even a relationship based purely on sex!

    - Pam Augé (~Wolfie~)

No meat was harmed during the making of this TV dinner.
    - Pam Augé (~Wolfie~)



StaceyG posted Mon, 13 March 2006 at 9:45 PM

Yes we are very very excited for the conversion of the Community to get under way.. It won't be long now:) Thank you for you're patience but it will be worth the wait!! Stac


Belladzines posted Mon, 13 March 2006 at 11:27 PM

if i can put in my two bobs worth - not sure if it will help.... if for example you paste the entire link from your browser to say your email to a friend.. remember to delete everything until you reach the part that says
ForumID=some numbers..

from:
for eg: http://www.renderosity.com/messages.ez?ForumID=4444442366&Form.ShowMessage=66615666

to:
http://www.renderosity.com/messages.ez?ForumID=4444442366

if you leave the entire address line intact that is in your browser chances are someone will log in as you... its a system thing and i've done it heaps of times... thankfully noone has used my name to do anything...

as i said that might not have been the problem..... but thought i'd share it.

AS :-)

Message edited on: 03/13/2006 23:28


-Wolfie- posted Tue, 14 March 2006 at 9:46 AM

Thanks AS. :-) We all know about this now, but there are some days when you forget, or people that don't know about the &Form.sess_id=## thing. ~Wolfie~

Helping everyone is the most rewarding failure you'll ever experience.
    - Ray Augé (~Wolfie~'s hubby)

Anything is more stable than Windows . . .
--- Even a relationship based purely on sex!

    - Pam Augé (~Wolfie~)

No meat was harmed during the making of this TV dinner.
    - Pam Augé (~Wolfie~)