News Focus
News Focus
icon url

cintrix

01/02/04 12:33 PM

#33782 RE: Tate202 #33781

Now that's scary!
icon url

Mattu

01/02/04 2:00 PM

#33785 RE: Tate202 #33781

I'm sure Bob will reply to this, but just to clarify what you mean...

A PM showed up in your inbox that wasn't really "written" to you correct?

You didn't just come up with a random number and read a private message out of the blue -- as in hacking PMs?

If so, we've seen this before. It's not a bug, but an issue on the client-side. When you click Private Reply, it puts a userID up there. You can reply to any message and change who you send it to -- intentionally or accidentally -- by changing the UserID. In each case I've heard of this, that's exactly what happened.

icon url

Bob Zumbrunnen

01/02/04 2:29 PM

#33800 RE: Tate202 #33781

Nevermind my PM to you. I figured out how it's happening.

I sure would've appreciated that revelation a little bit differently, though. As worded, it looks like you can read anyone's PM's at your discretion. Not the case.

Everyone, what was apparently happening was this:

1. User A receives a PM from User B.

2. User A clicks the "Private Reply" link and gets redirected to a reply screen.

3. The reply screen contains a couple of parameters in the URL: the UserID of the person to whom they're replying, and the number of the message to which they're replying.

4. User A, for reasons that completely escape me, changes the UserID part of the URL to the UserID of some other user (User C) and hits Enter.

5. User A types in their reply to User C, then Submits the post.

6. User C reads the PM and in the "In Reply To:" box sees the PM written by User B.

So it's not that people can pull up PM's written by others. It's that recipients of PM's can, with minor trickery, show the PM to someone else.

"Could" rather than "Can", actually. I just fixed it. Extra overhead, that I resent having to spend, but now when you're replying to a PM, the system checks to make sure you're really replying to the PM's author.

This might suggest to people that it was also possible to change the message number part of the URL and resubmit it, viewing someone else's PM, but that's not the case. When that's attempted, the system redirects you to your mailbox.

Also, it never was possible to "follow the chain" back any further than the message that was being redirected in reply. In other words, clicking the "Go To This Message" link wouldn't take you to that PM so you could see what it was replying to.