Staples.com -> Security Flaw -- What should I do

Page 2 - Seeking answers? Join the AnandTech community: where nearly half-a-million members share solutions and discuss the latest tech.

Monkeytool

Member
Apr 2, 2005
187
0
0
Originally posted by: dbleoslow
One way to get around this is to change your IP address to: 127.0.0.1. This is the "safety IP" that will keep this sort of thing from happening.

:laugh: :laugh: :laugh:

And stay there!
 

Lemodular

Senior member
Sep 15, 2004
521
1
71
LOL.....that's hilarious

Originally posted by: Quasmo
try typing in "poop" in the search engine see what comes up then tell me how smart the web devs are at Staples. All for laughs try "poorly manufactured parts" I had alot of time to play around while working there. Their website needs a HUGE overhaul.





From the search:
We have 2256 product(s) on our site containing poorly manufactured parts.
The following results matched your search:

Electronic Label Maker Tapes    Visit this category    for an exact match

 

WA261

Diamond Member
Aug 28, 2001
4,631
0
0
Originally posted by: JuicyLucy
Learn first how to make a proper HOT DEALS thread you AOL retard



Yeah, this is they type of comment we just love here at Anand....
 

emeraldsky

Banned
Dec 3, 2004
607
0
0
Originally posted by: JuicyLucy
Learn first how to make a proper HOT DEALS thread you AOL retard
This is known as thread crapping.
It is also know as flaming.
Neither one are permitted here.

 

alm4rr

Diamond Member
Dec 21, 2000
4,390
0
0
Originally posted by: JuicyLucy
Learn first how to make a proper HOT DEALS thread you AOL retard

God, what is your major malfunction

So far, every time I see you post in HD, all you do is spit vileness
Get real noob
 

AnyMal

Lifer
Nov 21, 2001
15,780
0
76
Originally posted by: JuicyLucy
Learn first how to make a proper HOT DEALS thread you AOL retard

You should get the sand out of your vagina :roll:
 

thedealmaker

Senior member
Jul 10, 2003
278
0
0
what's the flaw? tell me, tell me, so I can blackmail Staples for millions of dollars and get all you guys' credit card.
 

statik213

Golden Member
Oct 31, 2004
1,654
0
0
Originally posted by: FPSguy
UN-BE-LIEVABLE. It's pretty obvious what the issue is from the fact that you have to use the same computer, that automatically logs in, and then look at the response e-mail from Staples. I confirm that my password is viewable in plain text as well.

I love how it says "// For security purpose, user can't use back button to browse the previous page.", and yet they make your password plainly visible. Clearly "eknizek" could have done a better job with that page.

LOL, looked at more of the source code just now... how lame!!!
ekizek needs to get fired
 

statik213

Golden Member
Oct 31, 2004
1,654
0
0
Originally posted by: thedealmaker
what's the flaw? tell me, tell me, so I can blackmail Staples for millions of dollars and get all you guys' credit card.

AM already working on it.... why would I share the cut?

 

sjwaste

Diamond Member
Aug 2, 2000
8,760
12
81
Why so much making fun of the OP over this? On other hot deals boards, its usually the members looking out for one another. Hey OP, send me a pm with how to reproduce the problem and tell me if you're using internet explorer, firefox, or a different browser. I'll try it with my own account and email staples with documentation on what I see. If its happening to more than one person, they should hear about it from others too. They'll be more apt to fix it.
 

Zontor

Senior member
Sep 19, 2000
530
0
0
OK, found it....>>LAME<< on Staples part....

Given that it is a session cookie, it will expire fairly soon (I'm guessing < 20 minutes) -- I haven't tested this, but will.

This isn't a *major* flaw, but it underscores the ability to always log out of sites, clear cache, clear cookies, close browser, etc.

Even then you can't stop dumbass things...

BTW: Looks like the code was updated 2/25/02 -- so this has been here for a while....
 

Zontor

Senior member
Sep 19, 2000
530
0
0
You are correct...not Session cookies....I looked into this a bit more and figured out what is going on. My bad.
 

ECartman

Senior member
Nov 16, 2002
756
0
0
Originally posted by: dbleoslow
Did you feel that breeze as the suttle joke raced over the top of your head

Actually I missed it too ... must have been too "suttle"
 

Kostya17

Senior member
Jun 26, 2001
348
0
71
This is clearly off-topic and should be locked. Hey mods, where are you?

Ok, let me help ya... Computer Geeks' 10% off coupon code is GEEKMOM

NOW there is a hot deal in this thread ;-)

Enjoy!
 

mscdex0

Platinum Member
Apr 10, 2003
2,868
0
0
Originally posted by: Kostya17
This is clearly off-topic and should be locked. Hey mods, where are you?

Ok, let me help ya... Computer Geeks' 10% off coupon code is GEEKMOM

NOW there is a hot deal in this thread ;-)

Enjoy!

Like you're one to talk, posting coupon codes.... :roll:
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |