The Down Range Forum

Member Section => Down Range Cafe => Topic started by: mosbear on January 07, 2009, 11:39:51 AM

Title: Sportsmansguide security breach.
Post by: mosbear on January 07, 2009, 11:39:51 AM
Just came across this discussion on M&P forum. If you are Sportsmansguide customer take a look:

http://mp-pistol.com/boards/index.php?showtopic=18332&st=0 (http://mp-pistol.com/boards/index.php?showtopic=18332&st=0)

 
Title: Re: Sportsmansguide security breach.
Post by: ericire12 on January 07, 2009, 11:42:36 AM
We need to light up Sportsmans Guide with emails and get this fixed!
Title: Re: Sportsmansguide security breach.
Post by: 1776 Rebel on January 07, 2009, 12:07:53 PM
Apparently was fixed or at least disabled a couple of days ago according to the m&p thread. I just tried some lookups and no dice.
Title: Re: Sportsmansguide security breach.
Post by: ericire12 on January 07, 2009, 01:02:03 PM
Apparently was fixed or at least disabled a couple of days ago according to the m&p thread. I just tried some lookups and no dice.

It is working for me..... used generic names like "Smith" and various zip codes and can find many different results.
Title: Re: Sportsmansguide security breach.
Post by: PegLeg45 on January 07, 2009, 01:15:44 PM
Didn't work for me. Maybe they got it fixed. I'd hate to stop buying from them.
Title: Re: Sportsmansguide security breach.
Post by: Big Frank on January 07, 2009, 06:43:03 PM
I tried common names like Smith and Jones and some different zip codes my city and for some of them one name and address came up. For some there were so many it wants to know which address, which I could enter from the phone book if I wanted. I tried Anderson and Williams too. Now I know the names and adresses of some complete strangers and exactly what they ordered. I clicked on the UPS tracking button and know exactly when each package was delivered too. It's scary that this information is available to anyone. People should have to sign into their own account to get any information, just like most other websites.
Title: Re: Sportsmansguide security breach.
Post by: tombogan03884 on January 08, 2009, 01:28:35 AM
I just tried it with a friends name and got his whole order history !  :(
Title: Re: Sportsmansguide security breach.
Post by: cooptire on January 08, 2009, 02:48:41 PM
Funny.......but not really, I too did some random names and inadvertently came up with our local Deputy Chief of Police's orders! This REALLY needs to be fixed. ( Duh!  ::) )
Title: Re: Sportsmansguide security breach.
Post by: Big Frank on January 08, 2009, 05:14:15 PM
Funny.......but not really, I too did some random names and inadvertently came up with our local Deputy Chief of Police's orders! This REALLY needs to be fixed. ( Duh!  ::) )


If you tell him about it maybe he can do something.
Title: Re: Sportsmansguide security breach.
Post by: mosbear on January 08, 2009, 05:38:24 PM
To fix this thing in the code is a peace of cake, when you are forcing the user to sign-up prior to any activity other then browsing. The problem is they don’t require permanent account to be created to make a purchase. They use "cookies" to identify the user and to keep track of the items in the basket. This could only be fixed by changing the business rules of the site, which they are not willing to do. Apparently one-off type of the transaction volume is high enough to justify their behavior. It is not a clear-cut case so; lawyers wouldn't work "pro bono" unless you are really harmed by this business practice. Creating a shit storm on the Internet could do the trick, but I am not 100% sure. ???
Title: Re: Sportsmansguide security breach.
Post by: ericire12 on January 08, 2009, 07:13:27 PM

If you tell him about it maybe he can do something.

Bingo! That is the way to go
Title: Re: Sportsmansguide security breach.
Post by: ericire12 on January 12, 2009, 02:58:08 PM
Looks like they require specific street address for each search now
Title: Re: Sportsmansguide security breach.
Post by: Big Frank on January 12, 2009, 08:11:38 PM
Looks like they require specific street address for each search now


Yep. Now anyone who wants to steal your information will need to look up your address first.