solarforceflashlight-sales.com - member list accessible by public

I'd suggest anyone concerned of their personal information to:

1. Go to http://www.solarforceflashlight-sales.com/member.php

2. Log in (with your own account)

3. Move mouse over the "Hi, <your name>" on the upper right corner

4. Select "Modify profile" -> remove name, telephone & address (= replace with some nonsense)

5. Save changes with "Update"-button

This will leave your email address visible, but effectively removes other personal information.

http://www.willtec.com.hk/services

Glad BLF can assist them in their ongoing learning.

H)

My personal info now reads:

Name: quijibo
Telephone: 99999999999999999999999
Address: Get some better web developers!

Thanks on the tip on how to update your profile the, changed mine!

Now how do you change the cost of all the lights to $1 ??? :smiley: Just kidding! :bigsmile:

Their admins are working on it! :party:

invalid entry please try again, chinese names do not begin with Q :stuck_out_tongue:

No freakin’ excuse for ANY of these companies to be so cheap and Lame when it comes to keeping info confidential. And they wonder why people are Paranoid.
It just gets old quick.
Sorry for the rant, I know there is nothing we can do about it, but we don’t have to be happy or complacent about it.

Later,
Need a Beer (BIG ONE)

Keith

This isn’t cool.

Same thing happened last year from Int-Outdoors with the sql. files being breached.

If you use paypal for the sale, then you should be safe.

FWIW, they’ve told me their sysadmin is working on it. I sent them information about the issue and what causes it and how to reproduce it and what the potential impact is and some ideas for fixing it, but it might take a little while since it’s not a trivial fix. There are some kludgy ways to work around it quickly, but a proper fix would require some pretty big changes.

It looks like they’ve made some good progress on the issue today. I would be surprised if anyone here can still abuse the site. The google results aren’t completely removed, and the fix isn’t quite complete yet, but it’s much better.

I’ve sent them new test results and a new measurement of the problem scope with instructions for how they can test any changes they make.

Google denied all of the removal requests I made and provided the same link as before. >.<

https://support.google.com/websearch/troubleshooter/3111061#ts=2889054,2889060

I just heard about this. Changed all my contact information and password last night except my email address. Should I be worried?

Planes are made from old flashlights.

has this issue been addressed? I wanted to place an order but I saw this.

Looks like it’s still in the same state as last time I checked… still sort of broken but very very unlikely to be abused because it’s no longer vulnerable to any of the tools people actually use to browse the web. With a bit of info about how to do it, one could still look up anyone’s full order history and such, and it might still be possible to edit the site’s data but I haven’t tried. However, the way in is no longer trivial or easy to notice.

I’m not sure if they’re planning to fix it further, since the rest of the work required for a proper fix might be somewhat expensive and the web dev company who made the site doesn’t seem to fully understand what they did wrong. Regardless, I still sent them a suggestion for a low-tech solution which could be implemented in an afternoon if they knew what they were doing.

What’s going on with this as of now? I’d really like to order several $2.99 body tubes but not if its still risky.

Just checked a moment ago and it doesn’t look like it has changed. I think they’ve done everything they’re going to do, even though I sent them instructions and a log of how the site security can be bypassed.

However, the issue is at least greatly minimized. It used to be easy and obvious; now it’s much more obscure.

Is there anything I can do on my end to help myself? Use a fake name or use my screen name instead of my real name?

I have a box of spare heads and tails so it’s very tempting to be able to build 4 p60 hosts for <$15 but not if it’s going to expose my info.