PSA -About Mcmaster's Website

A place for general potato gun questions and discussion.
User avatar
pizlo
Corporal 3
Corporal 3
Posts: 783
Joined: Fri Dec 22, 2006 7:27 pm
Contact:

daberno123 wrote:
Edit: Pizlo beat me in finding it
Image
User avatar
Pete Zaria
Corporal 5
Corporal 5
Posts: 954
Joined: Fri Mar 31, 2006 6:04 pm
Location: Near Seattle, WA

This is indeed a big security vulnerability. It not only allows for potential privacy breeches, but opens the door to session hijacking and capturing of financial information.

socoj2, I'm going to remove the links you posted with your personal mcmaster link, for privacy and legal reasons.

Peace,
Pete Zaria.
User avatar
PCGUY
Owner
Owner
United States of America
Posts: 1437
Joined: Wed Aug 18, 2004 10:54 pm
Location: Illinois
Has thanked: 2 times
Been thanked: 28 times
Contact:

I have contacted McMaster.
Yes, I am the guy that owns & operates SpudFiles (along with our extremely helpful moderators).
User avatar
Ragnarok
Captain
Captain
Posts: 5401
Joined: Tue Dec 19, 2006 8:23 am
Location: The UK

Bloody hell, that really is a serious security flaw...

The way they've tried to get around it is just irresponsible.
Mind you, I never store any of my financial data on my computer or online, nor do I use automatic login on any internet store (forums - yes, just about everything else, no).

I'm not one to be careless with my details, so when I order, I'll manually enter my debit card number each time, and only after performing a full sweep of my PC for any possible phishing software.

I don't intend to fall foul of any scams, frauds, hacks or exploits.
Does that thing kinda look like a big cat to you?
socoj2
Specialist
Specialist
Posts: 169
Joined: Fri Jun 29, 2007 9:17 am

Heh I actually know what im doing. Its cool that some of you guys where not ready to believe me but. I blasted them in an email.... I am not happy at all. I checked my account when i found out about it and there was no outrageous errors. But someone did order a QEV and had it shipped to me. i also cancled that.
socoj2
Specialist
Specialist
Posts: 169
Joined: Fri Jun 29, 2007 9:17 am

pizlo wrote:Holy Crap, If I go to your current order I can see your info...
I don't know if you did this but it doesn't still have your credit card number.
Image




Image
that is because i DELETED my info from their site as soon as i found out about it...
socoj2
Specialist
Specialist
Posts: 169
Joined: Fri Jun 29, 2007 9:17 am

Just got a Mcmaster customer service rep. If you look at the bottom of their web page. Click on Security. It has two options Normal and VERY HIGH.

Very High will prompt you for an user name and password Every time to log into to your account.

I still consider the fact that it doesnt default to this blatantly stupid, and it pisses me off that they even took this chance with my account information.
User avatar
jimmy101
Sergeant Major 2
Sergeant Major 2
United States of America
Posts: 3210
Joined: Wed Mar 28, 2007 9:48 am
Location: Greenwood, Indiana
Has thanked: 7 times
Been thanked: 18 times
Contact:

socoj2 wrote:Just got a Mcmaster customer service rep. If you look at the bottom of their web page. Click on Security. It has two options Normal and VERY HIGH.

Very High will prompt you for an user name and password Every time to log into to your account.

I still consider the fact that it doesnt default to this blatantly stupid, and it pisses me off that they even took this chance with my account information.
That really doesn't address the security issues, and someone should tell McMaster that.

Besides, it looks like critical information is being passed in URLs. That should never happen. Clearly this is a bug in the system. Autologin is bad enough but at least with that, if you send a link to another person, persumably on another machine, then the autologin shouldn't work and your accout info (except perhaps the user name) would still be protected.
Image
clide
Corporal 3
Corporal 3
Posts: 784
Joined: Sun Mar 06, 2005 3:06 am
Location: Oklahoma, USA
Been thanked: 1 time

If you want to link to a product on McMaster you can use the following format:

http://www.mcmaster.com/nav/enter.asp?partnum=9528K131

Just replace the part after "=" with the part number you want to link to.
<a href="http://gbcannon.com" target="_blank"><img src="http://gbcannon.com/pics/misc/pixel.png" border="0"></a>latest update - debut of the cardapult
Post Reply

Create an account or sign in to join the discussion

You need to be a member in order to post a reply

Create an account

Not a member? register to join our community
Members can start their own topics & subscribe to topics
It’s free and only takes a minute

Register

Sign in

  • Similar Topics
    Replies
    Views
    Last post
  • Website Help!
    by Maniac » » in Website Discussion
    10 Replies
    2988 Views
    Last post by Maniac
  • need help with a website
    by Bully Dog Airsoft » » in Pneumatic Cannons
    3 Replies
    1557 Views
    Last post by jrrdw
  • My website
    by clide » » in General Cannon Discussion
    5 Replies
    2014 Views
    Last post by mark.f
  • mcmaster QEV
    by rp181 » » in Pneumatic Cannons
    1 Replies
    841 Views
    Last post by PVC Arsenal 17
  • McMaster
    by squeaks » » in Off-Topic Hobbies
    3 Replies
    1360 Views
    Last post by CS