I've got a problem that should terrify everyone (Full Version)

All Forums >> [Community Discussions] >> Perv to Perv Assistance



Message


Strangedesires90 -> I've got a problem that should terrify everyone (7/14/2017 12:21:10 PM)

When I click on the different pages, it logs me in as a different user and I see their version of the page instead.
Example:
When I click "Who's viewing me" It says "Logged in as dawndalis " and I see all of the people that have viewed her.

When I click "edit profile" Suddenly I'm Cooper1972 and all of his details and the ability to change them are in front of me instead of my own. He is also my "My account page and I can see/change his email.

"Admirers" page makes me user TNDom23

My Mail makes me MountainManCO(Who really needs to check his mail!!!)

Favorites is loveangelm.

And on and on and on.
And I think I'm actually logged in as them as well because every new page changes my notifications of viewings and mail.





Lawrence111 -> RE: I've got a problem that should terrify everyone (7/25/2017 12:52:08 PM)

I find it interesting that no one has commented between 7/14/17 when OP posted and today (7/25/17).

The Ancient saying: "What did you pay for a CM/CS account? Then demand a refund and leave if you do not like it," seems to ring particularly ... odd.

I would however add my voice to the OP's. This is more than most concerning :(




MsLadySue -> RE: I've got a problem that should terrify everyone (7/25/2017 3:14:31 PM)

Perhaps no one commented because most people have not experienced this problem. Even if we did, we couldn't help him. There seems to be no one supplying support for these sites and the owner is doing nothing to upgrade the outdated software used to run them. Luckily we're not paying for the use of either site.




ThatDizzyChick -> RE: I've got a problem that should terrify everyone (7/26/2017 1:08:22 PM)

This site is completely broken, and the guy who owns it is apparently perfectly happy with that state of affairs.




Lawrence111 -> RE: I've got a problem that should terrify everyone (8/22/2017 7:11:52 PM)

I'll try to describe the steps to achieve this strange behavior:

- Look at a profile, the "small" view first.

- Click on the photo or click "View Full Profile", which take you to the large view, if you will.

- Note that my log-in name (in the upper right corner) is listed not as me but as someone else. This name can be the same on a consistent basis or can be someone else.

- Click on "Send photos" (which never actually works any more) to send an email to which I can attach a photo, and see my user name in the corner.

- Very strange and likely insecure ?

Sincerely,

Lawrence




Cruelcontrolcpl -> RE: I've got a problem that should terrify everyone (8/23/2017 2:11:13 AM)

Yup i can replicate and i am not versed in coding, but spent a bit of time scanning thru the source and nothing stood out to me - the random username shows up once but afaics all the user ID's match respective accounts (random user not linked there at all)




Cruelcontrolcpl -> RE: I've got a problem that should terrify everyone (8/23/2017 2:13:26 AM)

:o




LadyPact -> RE: I've got a problem that should terrify everyone (8/23/2017 2:05:00 PM)


quote:

ORIGINAL: Lawrence111

I'll try to describe the steps to achieve this strange behavior:

- Look at a profile, the "small" view first.

- Click on the photo or click "View Full Profile", which take you to the large view, if you will.

- Note that my log-in name (in the upper right corner) is listed not as me but as someone else. This name can be the same on a consistent basis or can be someone else.

- Click on "Send photos" (which never actually works any more) to send an email to which I can attach a photo, and see my user name in the corner.

- Very strange and likely insecure ?

Sincerely,

Lawrence


I can verify that this method works.




Lawrence111 -> RE: I've got a problem that should terrify everyone (8/23/2017 7:12:07 PM)


quote:

ORIGINAL: Cruelcontrolcpl

Yup i can replicate and i am not versed in coding, but spent a bit of time scanning thru the source and nothing stood out to me - the random username shows up once but afaics all the user ID's match respective accounts (random user not linked there at all)


Cruelcontrolcpl, I sent you a private note. You are welcome to respond.




johnsteed2 -> RE: I've got a problem that should terrify everyone (8/26/2017 10:51:42 AM)

Yeah -- I noticed this problem recently myself, and sent a Support note (wondering if it was related to the "can't attach pictures" problem). As has been usual for the past year or so, no response from Support.

To be honest, in the past, I was always surprised that when I sent a message to Support, that I would get a message, given that this is a free site. But that has changed. No response to any of my Support messages about the "Profile not found" error when attempting to attach pictures, or this "suddenly you're someone else" scary issue.




Bittenkiss -> RE: I've got a problem that should terrify everyone (9/15/2017 9:55:01 AM)

I am beginning to think its a cache problem - when you view a profile, the site is possibly building a page to view and storing it in a cache. Then, when someone else views the profile (and nothing has changed) instead of building a new page with all the same stuff, it simply shows you the one it did earlier - from the cache. Trouble is, you get the cached display from the user who first viewed it, and their name appears int he top right corner.

I think its the site admin trying to improve the site performance and not a hack or security issue at all.




Lawrence111 -> RE: I've got a problem that should terrify everyone (9/15/2017 8:59:58 PM)


quote:

ORIGINAL: Bittenkiss

I am beginning to think its a cache problem - when you view a profile, the site is possibly building a page to view and storing it in a cache. Then, when someone else views the profile (and nothing has changed) instead of building a new page with all the same stuff, it simply shows you the one it did earlier - from the cache. Trouble is, you get the cached display from the user who first viewed it, and their name appears int he top right corner.

I think its the site admin trying to improve the site performance and not a hack or security issue at all.


So Bittenkiss, if I understand you, might the answer be something as simple as ... refreshing the page? Thanks.




MsLadySue -> RE: I've got a problem that should terrify everyone (9/15/2017 9:04:04 PM)

As mentioned earlier in this thread, the owner of this site and the profile side, is NOT DOING any upgrades and hasn't done so since the name was changed to CollarSpace. He's quite content to leave things just as they are.




DesFIP -> RE: I've got a problem that should terrify everyone (9/15/2017 9:12:09 PM)

The owner is quite ill and unable to run the business. He's had offers to sell but declined all.




Bittenkiss -> RE: I've got a problem that should terrify everyone (9/16/2017 5:59:50 AM)


quote:

ORIGINAL: Lawrence111


quote:

ORIGINAL: Bittenkiss

I am beginning to think its a cache problem - when you view a profile, the site is possibly building a page to view and storing it in a cache. Then, when someone else views the profile (and nothing has changed) instead of building a new page with all the same stuff, it simply shows you the one it did earlier - from the cache. Trouble is, you get the cached display from the user who first viewed it, and their name appears int he top right corner.

I think its the site admin trying to improve the site performance and not a hack or security issue at all.


So Bittenkiss, if I understand you, might the answer be something as simple as ... refreshing the page? Thanks.



No, chances are the page is built on the server and stored there. Refreshing will simply fetch the same pre-built page again.

What might need to happen is for the page you're looking at to change in some way, like the user you're looking at changes their details (or possibly just wait, as the cached page might be discarded and refreshed after a set time - that's quite common).

Either way, apart from the name, it doesn't seem to be a problem. Don't put any personal details on the site if you're worried, but that's probably good advice regardless!




Bittenkiss -> RE: I've got a problem that should terrify everyone (9/16/2017 6:02:02 AM)

Interesting - but then I did see the site being added and removed from cloudflare recently, so I figured something was being done, even if it was in the realm of networking/administration rather than actively managing the site itself.

Maybe its cloudflare that's implemented the caching then!




submgreenbay -> RE: I've got a problem that should terrify everyone (9/16/2017 10:23:35 PM)

There were a few other quirks I noticed in the last few weeks. Clicking the View Interest tab on someones profile would log me out of the site. And some times the template stuff like the words Username, Description, etc would be in a different language.




sexysarah -> RE: I've got a problem that should terrify everyone (9/18/2017 3:48:23 PM)

Actually, you should be more terrified than you realize.

There's some Javascript code that's been 'infecting' people's profiles. I noticed it yesterday, but it definitely appears to be spreading. I'm not a programmer so I don't fully understand what it does, but long story short, it appears that if someone puts Javascript code within their profile, it executes when you view their full profile. So it's adding the infectious code to everyone's profiles, and also doing something with people's cookies.

I collected the details of what I found: https://pastebin.com/FXVu6N3v

Here's what it looks like in someone's profile:

[image]https://i.imgur.com/Zm02L1D.jpg[/image]

...This site is a dumpster fire, and not just because of the userbase.

(Oh, and uh, also, you should have no pretense of security here. It's not an encrypted site.)




Lawrence111 -> RE: I've got a problem that should terrify everyone (9/18/2017 8:49:04 PM)

So thanks for this information, SexySarah.

As I wrote to you, would you know:

- how does one delete any malicious code that may be in one's profile ?

- Will this code do anything outside of CS, that is: are individual computers at risk?

Thanks.




sexysarah -> RE: I've got a problem that should terrify everyone (9/19/2017 9:22:48 AM)

It appears to contact some other site (or set their referral link for this other site?) But I'm not a programmer so I can't tell. But yeah this site isn't secure at all. I'd recommend making sure you use a unique password for this site.




Page: [1] 2   next >   >>

Valid CSS!




Collarchat.com © 2024
Terms of Service Privacy Policy Spam Policy
0.296875