PDA

View Full Version : SmugMug Security Hole?


darryl
Jan-29-2008, 02:45 PM
Well, kind of, but not really, if you've been a SmugMug user for a while:

http://blogoscoped.com/archive/2008-01-28-n59.html
http://blogs.smugmug.com/don/2008/01/28/your-private-photos-are-still-private/
http://blogs.smugmug.com/don/2008/01/28/first-two-security-winners/

As I commented on Don's last post, I really would love a little transparency (http://www.dgrin.com/showthread.php?p=737595#post737595) into the "hacks" used to win the prize. Especially if the holes have now been fixed.

I've known about the CNAME redirect for awhile, but never really considered it a bug, since I actually am looking for a way to *find this information* (http://www.dgrin.com/showthread.php?t=81854).

Anyways, interesting stuff though. I'm bummed I missed my chance to make some money!

Andy
Jan-30-2008, 04:09 AM
Hi Darryl, thanks for posting this!
I'd suggest that over here: http://www.dgrin.com/showthread.php?t=82969
would be a neat place to carry on some discussion.... thanks so much!