news | articles | reviews | software | modules | accessories | discussion | faq | mobile | store
VisorCentral.com >> Discussion >> Visor Related >> Springboard Modules
Innogear Security issue!!

Post a New Thread | Post A Reply

  Last Thread   Next Thread
Author
Topic: Innogear Security issue!!    
LarryN
Member

Registered: Jun 2000
Location: Pembroke,MA
Posts: 307

Exclamation

** Please Read If You Ordered Anything From Innogear **

I found out the hard way, that the cookie that you get from store.innogear.com does not need to be present for users to access your account information!

I have a MiniJam on backorder @ Innogear. I posted reply to a message on a non-visor related messageboard that somebody asked how the visor plays music. So, being the helpful guy that I am, opened another browser window, opened the Innogear website, nad went to the Minijam page. I then copied the url, and posted it the my message.

I then received an anonymous email from some very honest person (thank goodness) that informed me that my link allows access to "My Account" information, inclusive of name, address, phone numbers, CREDIT CARD NUMBER (complete with card type and expiration date!!!).

I already cancelled my credit card, and asked the mesageboard owners to remove my post (which they have yet to do!). I also called innogear to tell them of the website design issue, they said that my circumstance is unfortunate, but they will not do anything about it!

So, since that creidt card listed there is no longer active, I can't even let Innogear know what my new card ifo is, of the original link that I (stupidly) posted would then display the new card info!!!

I'm letting you all know this because it could happen to you to. I asked Innogear to not display my full credit card info (It should only be showed at time of placing order to confirm the number IMHO), and they would not change the field attributes on the credit card fields of the webpage...

gggrrrrrr...

LarryN is offline Old Post 08-18-2000 03:39 PM
Click Here to See the Profile for LarryN Edit/Delete Message Reply w/Quote
LarryN
Member

Registered: Jun 2000
Location: Pembroke,MA
Posts: 307

Cool

*** Update ***

Innogear has informed me that they have corrected this security issue with their site, and having cancelled my credit card (awaiting replacement), there were no new charges posted to it.

On the good news side... They are sending me a no-charge 64mb MiniJam in ice color! So, for the trouble, I guess I'm pretty satisfied.

Once I talked the the correct people, they were verry helpful.

LarryN is offline Old Post 08-18-2000 11:32 PM
Click Here to See the Profile for LarryN Edit/Delete Message Reply w/Quote
All times are GMT. The time now is 04:00 AM. Post New Thread    Post A Reply
  Last Thread   Next Thread
[ Show a Printable Version | Email This Page to Someone! | Receive updates to this thread ]

Forum Jump:

Powered by: vBulletin Version 2.3.4
Copyright ©2000, 2001, Jelsoft Enterprises Limited.