Nav: Home
Welcome, Guest. Please login or register.
Did you miss your activation email?
May 26, 2012, 12:29

Login with username, password and session length

MicrostockGroup

Microstockgroup Sponsors


« previous next »
Pages: [1] Print

Topic: URGENT! Security failure at Stockxpert!  

(Read 2894 times)
XPTO


« on: December 21, 2010, 04:24 »

URGENT

Today, after I've accessed the stockxpert site I've noticed I was logged on into another member account!

It seemed my log-in was still active from my last access but it directed me to another member account.

I even checked the downloads, saw the accumulated money, etc., and I even think I could have changed the payment address and ask the money (haven't checked) since all was normal in the site and only after a while I've noticed it wasn't my account.

This is extremely serious and I wonder if someone is accessing my account too.

Please verify this situation, and contact StockXpert support if you verify this too..


Ignore | Logged


DepositPhotos.com
Danicek


Dreamstime GaugeiStock Gauge
« Reply #1 on: December 21, 2010, 04:36 »

I see my account as usual...


Ignore | Logged


cclapper
« Reply #2 on: December 21, 2010, 07:13 »

URGENT

Today, after I've accessed the stockxpert site I've noticed I was logged on into another member account!

It seemed my log-in was still active from my last access but it directed me to another member account.

I even checked the downloads, saw the accumulated money, etc., and I even think I could have changed the payment address and ask the money (haven't checked) since all was normal in the site and only after a while I've noticed it wasn't my account.

This is extremely serious and I wonder if someone is accessing my account too.

Please verify this situation, and contact StockXpert support if you verify this too..

This has happened to others in the past as well. Not something new. Never seems to get fixed.
I just don't think IS cares about this stuff anymore.


Ignore | Logged


Microbius
« Reply #3 on: December 21, 2010, 07:56 »

That's what I was going to say. I remember a similar thread not too many months ago.
I think IStock has so many mistakes to clean up at the moment getting it sorted must be on the end of a very long list!


Ignore | Logged


Danicek


Dreamstime GaugeiStock Gauge
« Reply #4 on: February 08, 2011, 04:17 »

So, I opened the StockXPert page today morning, logged into my account and then navigated away. When I returned to the page bit later during the same browser session, I noticed that I'm still logged in but to a different account (with much greater balance). I thought 'crap'. Logged out and logged in again with my credentials. And so I was back to my account. Then I checked my balance just to notice someone has requested payment at 2:26 AM my time yesterday (when I was asleep).

My profile still has the same correct paypal address. I don't know if it is possible for someone to change it, request payment and then change it back, so that I don't notice anything. I'm not sure if payment address is recorded at the moment of payment request and goes with the payment or if it is used at the moment of payment processing from the account.

Anyway, this is real crap.

EDIT: I've contacted support and requested them to verify the payment is going to correct Paypal address. Anyhow, this is pretty serious security issue.
« Last Edit: February 08, 2011, 04:27 by Danicek »

Ignore | Logged


grp_photo


« Reply #5 on: February 08, 2011, 10:47 »

This leads to one question does the Stockagencies in general control if the Paypal-Account is registered to the same name as the contributor or do simply transfer using the email and don't even look at the real name or maybe even can't?

Does anybody now this?


Ignore | Logged


WarrenPrice

Dreamstime GaugeiStock Gauge
« Reply #6 on: February 08, 2011, 11:03 »

This (the login/account problem) is not a new "feature."  It has happened to me more than once and I have reported it more than once. 

All occurrences were after StockXpert was acquired by that other entity.


Ignore | Logged


microstockphoto.co.uk


Dreamstime GaugeiStock Gauge
« Reply #7 on: February 08, 2011, 11:18 »

that entity is a community and money doesn't make you happy - so what's the matter if someone else can access your account and ask for a payout instead of you?
« Last Edit: February 08, 2011, 11:25 by microstockphoto.co.uk »

Ignore | Logged


Danicek


Dreamstime GaugeiStock Gauge
« Reply #8 on: February 08, 2011, 13:40 »

This (the login/account problem) is not a new "feature."  It has happened to me more than once and I have reported it more than once.  

All occurrences were after StockXpert was acquired by that other entity.

Yes, I know it is not new, although this is the first time it happened to me. What makes it special (at least for me :]) is that someone went ahead and requested the payout of may $58.


Ignore | Logged


lisafx
« Reply #9 on: February 08, 2011, 14:08 »


Yes, I know it is not new, although this is the first time it happened to me. What makes it special (at least for me :]) is that someone went ahead and requested the payout of may $58.

Exactly!  That certainly takes the issue to a whole new level.  And of course it demonstrates the real and significant danger of this particular bug.   Shocked


Ignore | Logged


caspixel



« Reply #10 on: February 08, 2011, 17:24 »

This (the login/account problem) is not a new "feature."  It has happened to me more than once and I have reported it more than once.  

All occurrences were after StockXpert was acquired by that other entity.

Yes, I know it is not new, although this is the first time it happened to me. What makes it special (at least for me :]) is that someone went ahead and requested the payout of may $58.

WOW! Shocked Shocked Shocked


Ignore | Logged


lightscribe

Dreamstime GaugeiStock Gauge
« Reply #11 on: February 09, 2011, 00:47 »

Wow!! This is unbelievable!  I guess we need to be very careful about logging out everytime we are done at StockXpert


Ignore | Logged


visceralimage


Dreamstime GaugeiStock Gauge
« Reply #12 on: February 09, 2011, 05:32 »

This (the login/account problem) is not a new "feature."  It has happened to me more than once and I have reported it more than once.  

All occurrences were after StockXpert was acquired by that other entity.

Yes, I know it is not new, although this is the first time it happened to me. What makes it special (at least for me :]) is that someone went ahead and requested the payout of may $58.

WOW! Shocked Shocked Shocked

Of course, it is possible someone else logged in, was directed to the wrong account-yours, saw the money and thought it was his account, requested a payment.  Hopefully, You will get your payment and hopefully the other guy or gal will find out this site is not secure and they did not have $58 dollars in their account.


Ignore | Logged


markrhiggins

Dreamstime GaugeiStock Gauge
« Reply #13 on: February 09, 2011, 05:54 »

 I don't know why you think this is serious. Not costing StockXpert anything so how is it serious?


Ignore | Logged


WarrenPrice

Dreamstime GaugeiStock Gauge
« Reply #14 on: February 09, 2011, 11:07 »

I don't know why you think this is serious. Not costing StockXpert anything so how is it serious?

That is sort of what I tried so ineptly to say.  It has been going on for about a year and has been reported several times.  They don't seem to care ... The Getty syndrome.


Ignore | Logged


madelaide
« Reply #15 on: February 09, 2011, 16:22 »

Just curious, was it a single event or are people reporting such problems?

IT people, humpf! Always messing up with software so they are needed eternally.  Grin


Ignore | Logged


Danicek


Dreamstime GaugeiStock Gauge
« Reply #16 on: February 11, 2011, 16:23 »

Just curious, was it a single event or are people reporting such problems?

It was not a single event, it happens to various people from time to time (as Warren points out for more than a year).

The support guy (Darek, obviously in charge of StockXpert stuff at IS) got back to me in timely manner and in very polite tone and said he will ensure the payment goes to my Paypal address. He did not said whether it was already going to my address or if someone indeed attempted to get the money.

Anyhow, he did not sound surprised to hear I just got to someone else account and someone else got to mine. Obviously a known bug.


Ignore | Logged


Phil



« Reply #17 on: February 11, 2011, 16:54 »

what?, glad I deleted my account. Somehow I think the priority for fixing anything on StockXpert would be absolutely zero.


Ignore | Logged


Danicek


Dreamstime GaugeiStock Gauge
« Reply #18 on: February 12, 2011, 11:28 »

Yes, apparently it is closed to zero. On the other hand they disclosing personal account information and allowing people to steal from others by not fixing it. That is rather serious issue.


Ignore | Logged


Envateo Photo ToolsMicrostock Insider
Pages: [1] Print 
« previous next »
Jump to:  


Related Topics
Subject Started by Replies Views Last post
We had a hardware failure
Microstock News
Dreamstime News 1 714 Last post July 11, 2007, 15:55
by takestock
We had a hardware failure
Microstock News
Dreamstime News 1 816 Last post July 11, 2007, 20:12
by dbvirago
Need Urgent Advise
Dreamstime.com
roman 7 1307 Last post August 01, 2007, 17:27
by hospitalera
urgent: outdoor large group portrait
Lighting
eyeCatchLight 11 2173 Last post October 10, 2010, 06:46
by Ploink
URGENT - Image folder simply disappeared
Off Topic
XPTO 24 989 Last post November 19, 2011, 04:59
by Batman

TinyPortal v1.0.5 beta 1© Bloc