View Full Version : Forum handle not my own
Snowdonia
07-04-2007, 09:40 AM
After the update to the forums where we got the nifty see the last post responded to thing, I had the old "new forums" problem of appearing logged out when I really wasn't. So I surfed the boards a bit until it began displaying "Logout[MW2K2]" (verifying that it recognized me as being logged in) then went to the main board page and resaved my bookmark. Today, I go to my bookmark, and I'm not who I am meant to be. It was displaying "Logout[Gwen]" and I have NO idea who this person is and even going to "My Profile" brings up this persons profile but switches the logout display to my own handle. This seems a bit of a security risk IMO and needs prompt looking into. I'll be closing this browser session and reopening the boards again to see if this persists but the fact this happened once should bring up the red light to look into it further.
Snowdonia
07-04-2007, 09:43 AM
Second try... Used bookmark and again was faced with a "not logged in" page. Going to "SIGN IN/CHANGE USER" displays me logged in and taking the "Forum Index" link from there again recognizes that I am indeed logged in. More on this as I close the browser and reopen the boards. EDIT: A few more attempts and initially surfing to the boards index displays me as not logged in. Going to any of the forums rectifies this and I display as being logged in. I've been unable to reproduce the [Gwen] handle in the 4+ attempts after it has happened. I'm using Firefox if this makes any difference.
Kethaera
07-04-2007, 04:25 PM
I've had the same thing happen to me. It showed me as signed out, so I went to sign in, and it said at the top: Logout[someotherperson]. I could see this other person's profile, but I didn't attempt to post as that person. I've only had it happen once, and I also use Firefox.
Gwenae
07-04-2007, 04:54 PM
<p>Well, THAT's interesting because when I pulled up this website it showed up as [someone elses handle], and after I logged out (after several attempts), I was finally able to log in as myself. It sounds like I found out who ended up with my account.</p><p>Someone needs to fix this as soon as possible. This is a security issue and it rates high up on the scale. After I post this note, I'm logging out so hopefully no one will find my handle where theirs should be.<img src="/smilies/e78feac27fa924c4d0ad6cf5819f3554.gif" border="0" alt="SMILEY" /></p>
Kalez
07-04-2007, 05:57 PM
i had the same thign happen to me recently, or something similar. i was getting errors trying to go into the forum, then when i backed up i saw a Logout [A____ Nightsword] (dont remember actual name). so i thought i ws being hacked er soemthing and changed my password. i use IE btw.
BanhammerStratics
07-04-2007, 06:34 PM
I had the same thing happen just a minute ago -- refreshed the main page and found that I was logged in, but not as myself -- instead, I was "Dasein", whoever that is. As soon as I clicked on the "Forum Help and Discussion" link, though, I was myself again.<a href="http://forums.station.sony.com/eq2/user/logout.m" target="_blank" rel="nofollow"> </a>
Kalez
07-04-2007, 08:09 PM
you know, this is getting irritating. ive been playing mmos for a while, sticking to mostly the free ones trying to find one that i like that doesnt have too many screwups, then i decide they dont have enough of a gaming experience so i move to p2p games. ff11 battle system was so slow, so i left that game and came to everquest2 after my friend showed me the beautiful change from eq1 lol. then, to my surprise, even though its a p2p, this game ALSO has tons of screwups... and its frm sony?!? what the heck are they doing... seems to be a major fad lately, putting out half-made, buggy games. and now there forum is also screwing up?
Nayurayne
07-04-2007, 08:09 PM
This has happened to me twice now. With two different people no less. The first thing I did was log out of them, or when that didn't work just switch user. It bothers me that this has been going on for a few days now but to be honest I have seen worse. My other game that I have played for three years the site is constantly being attacked by a virus because of careless owners. They don't do anything to fix the problem of course, although I imagine that SOE is better then that. I hope this problem gets fixed soon. To any whose account I might end up in I promise I won't touch a thing.
Kalez
07-04-2007, 09:12 PM
i keep getting frozen from the forum and guess what, after i restarted my pc (yeah full freeze), i only opened IE and as i came upon the eq2 site, not even tried to sign in yet, there was a Logout[Calthine], then when i went to her profile to maybe leave her a message er something, it logged everything out. and people say all the problems are our pcs... HA!
Snowdonia
07-05-2007, 08:03 AM
Got a new person I was logged in as today. Nantusai or something like that. Clicked the "Logout" several times to try and log out of that person and it NEVER took. Had to click on the "Sign in/Change User" link at the very top to be able to log myself in. Can we at least get SOME indication this is being looked into? I doubt people are appreciating the knowledge that someone else is temporarily being given access to their forum account and goodness knows what else. If this hasn't been acknowledged or addressed before it happens again, I'll take my testing even farther and actually try and change things to whomever's account I get stuck with and fish a little deeper into seeing how much of a security risk this really is.
aardda
07-05-2007, 10:37 AM
<p>I just got this....</p><p><b>You have been banned.</b> You may NOT post or place in a signature any material that attacks or insults others on the forums; or engages in name-calling, harassment, or threats. Furthermore, you may not "troll" the forums. "Trolling" is defined as: Posting with the intent of stirring up trouble or to incite disruption. An example of trolling would be posting to a thread without the intent to provide constructive suggestions or comments and instead making disruptive comments. In general, you may post any material written in a courteous and mature manner, providing that it is on-topic for the forum to which you are posting. This includes material that disagrees with the way that we, the developers, operate the game. We will not interfere with the communication of thoughts and ideas as long as the presentation is constructive and appropriate for all those capable of reading the forum. </p><p>but could still see the forums and had me logged in as someone called dancemice. Tried clicking on the profile and it switched me back to my real one. Looks like a major account security burp if its mixing up login sessions.</p>
Grimwell
07-05-2007, 01:17 PM
Thanks for the information. I'm getting this to the forum team.
Gwenae
07-05-2007, 01:20 PM
You're welcome. I PM'd him because I was unsure if anyone had seen this thread. Maybe they'll fix this now.
Catria
07-05-2007, 01:31 PM
<cite>aarddave wrote:</cite><blockquote><p>I just got this....</p><p><b>You have been banned.</b> You may NOT post or place in a signature any material that attacks or insults others on the forums; or engages in name-calling, harassment, or threats. Furthermore, you may not "troll" the forums. "Trolling" is defined as: Posting with the intent of stirring up trouble or to incite disruption. An example of trolling would be posting to a thread without the intent to provide constructive suggestions or comments and instead making disruptive comments. In general, you may post any material written in a courteous and mature manner, providing that it is on-topic for the forum to which you are posting. This includes material that disagrees with the way that we, the developers, operate the game. We will not interfere with the communication of thoughts and ideas as long as the presentation is constructive and appropriate for all those capable of reading the forum. </p><p>but could still see the forums and had me logged in as someone called dancemice. Tried clicking on the profile and it switched me back to my real one. Looks like a major account security burp if its mixing up login sessions.</p></blockquote><p>I got the same thing....... sounds like someone managed to hack into the forums perhaps?? At the very least this is definitely a major security issue and now I'm concerned about my account.</p>
SaraBH
07-05-2007, 01:36 PM
i just had this happen to me to? Logged in to the forum and a big "You are baned" paragraph appeared. I dont really post allot and its very rare when i post anything that is not constructive so i didnt think i should be baned. Then i saw that i was not me......i tryed logging in as myself and it took a few trys.
Grimwell
07-05-2007, 01:49 PM
A few headlines now that I'm caught up on what the team knows and is doing so far: <ol><li>The majority of people visiting the forums are not seeing this. It's an exception, which is good.</li><li>Your account security is not at risk. It seems that the server is sending you the cached page that another user requested/saw but you are not actually getting access to their account (you have yet to authenticate).</li><li>Refreshing the page should clear it and let you log in as normal (you may need to refresh more than once).</li></ol>The key point being that your account is not at risk. The forum team is working actively on sourcing why the cache is sending pages out to the wrong people, and fixing that.
Mareth
07-05-2007, 02:23 PM
<cite>Grimwell wrote:</cite><blockquote>A few headlines now that I'm caught up on what the team knows and is doing so far: <ol><li>The majority of people visiting the forums are not seeing this. It's an exception, which is good.</li><li>Your account security is not at risk. It seems that the server is sending you the cached page that another user requested/saw but you are not actually getting access to their account (you have yet to authenticate).</li><li>Refreshing the page should clear it and let you log in as normal (you may need to refresh more than once).</li></ol>The key point being that your account is not at risk. The forum team is working actively on sourcing why the cache is sending pages out to the wrong people, and fixing that. </blockquote>If I understand this correctly, doesn't this mean that you could potentially get to view someone else's PM's? Or at the very least the inbox with sender and topic? While it doesn't put the account at risk, it certainly hits in the privacy sector.
-Sentinel-
07-05-2007, 04:08 PM
<cite>Mareth wrote:</cite><blockquote>If I understand this correctly, doesn't this mean that you could potentially get to view someone else's PM's? Or at the very least the inbox with sender and topic? While it doesn't put the account at risk, it certainly hits in the privacy sector. </blockquote>No, this is only affected on the forums/list.m and forums/show.m pages when you aren't logged in which only list the forums and topics. So when you go to the private messages, those pages aren't cached.
Gwenae
07-05-2007, 04:27 PM
Snowdonia@Runnyeye wrote: <blockquote>Today, I go to my bookmark, and I'm not who I am meant to be. It was displaying "Logout[Gwen]" and I have NO idea who this person is and even going to "My Profile" brings up this persons profile but switches the logout display to my own handle. This seems a bit of a security risk IMO and needs prompt looking into. </blockquote>Ok, but wait, she was able to see my profile. So I think there IS a problem here, and I'd really appreciate it if you considered the privacy aspect of it. Thanks.
Priestbane
07-05-2007, 06:17 PM
<p>It happened to me too. As in, I showed up on the boards and showed as logged in under someone else's handle. The first thing I did was try to access the profile, because if I could, then it would be something serious. It absolutely did not allow me access to the profile for that handle; it only showed me the public information.</p><p>I don't think there's a loss of privacy here.</p>
Priestbane
07-05-2007, 06:24 PM
<p>EDIT: Double post; maintenance weirdness.</p>
Gwenae
07-05-2007, 07:05 PM
<p>I disagree. She was able to view my profile, therefore she could change settings if she wanted to. Unless she can clarify, and tells me that she could not do this, I will then be satisified. I will remain concerned until they've fixed it.</p>
Grimwell
07-05-2007, 07:08 PM
<a href="http://forums.station.sony.com/eq2/posts/list.m?topic_id=370201" target="_blank" rel="nofollow">As per this note</a>, this should no longer be a problem! Please shoot me a PM if you see anything wonky.. well other than me. <img src="/smilies/e8a506dc4ad763aca51bec4ca7dc8560.gif" border="0" alt="SMILEY" />
Snowdonia
07-05-2007, 07:12 PM
Gwen, When I went to "My Profile" when I had your account it showed me your profile as it displays to the public. I did not try and dig deeper to see how much further I could go (IE edit) because I am a firm believer in reporting first before taking drastic measures to test. IMO, it would have been a drastic measure to try and edit your profile. So unfortunately, I can't answer that question for you. I can only assure you that I myself, while having your account displayed to me, did now venture down that road. Hopefully you can take a small bit of solace in that.
Gwenae
07-05-2007, 07:23 PM
<p>Thank you! I am so happy to hear that! Ok, I'm no longer worried and I appreciate the clarification!</p>
vBulletin® v3.7.5, Copyright ©2000-2025, Jelsoft Enterprises Ltd.