Jump to content

Amazon Slipup


H2O

Recommended Posts

As pointed out in our spam discussion forum (here) Amazon has a programming slip-up that allows any email address to be viewable, by any anonymous user, just by entering www.amazon.com/seller/nickname where "nickname" is a registered amazon users nick.

 

Try yours, for example. Or "Jeffbezos". To see the email, click on "view new seller profile page" and look carefully in the grey area at the bottom. This leak seems totally unrelated to any privacy settings you may have on your Amazon account.

 

Spammers with screen-scraping tools will take advantage of this within a heartbeat. Unhappy with a book review? feel free to flame the reviewer directly. It is disappointing that Amazon has not heeded complaints by more than one customer over this breach. Too busy handling the Xmas rush, perhaps?

 

News can be found here: http://www.dslreports.com/shownews/36680

 

The above snippet is from broadbandreports.com and as of time of posting this message I tried the URL on several different nicknames and sure enough I was able to access that person's data [e.g email address]

 

Quite scary!!

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...