By Cristiano on Monday, 24 March 2014
Posted in Technical Issues
Replies 13
Likes 0
Views 1.1K
Votes 0
Security bug, after Account Activation Email Request

The user is required to make activation email,

If you change your email, after confirming it, he will again be a user-pending and will receive another e-mail to activate your account.


Not so with easysocial is a security flaw.
You mention V1.2.4 - is it available somewhere? or did you mean v1.2.3?
·
Monday, 24 March 2014 08:27
·
0 Likes
·
0 Votes
·
0 Comments
·
You mention V1.2.4 - is it available somewhere? or did you mean v1.2.3?


Yes, v.1.2.3, already fixed the title, thanks
·
Monday, 24 March 2014 08:37
·
0 Likes
·
0 Votes
·
0 Comments
·
Cristiano wrote:

You mention V1.2.4 - is it available somewhere? or did you mean v1.2.3?


Yes, v.1.2.3, already fixed the title, thanks


I thought I missed the location to get v1.2.4 - Mark and the team are probably fixing things reported and we might see another version soon. But for the most part v1.2.3 is very stable.
·
Monday, 24 March 2014 08:54
·
0 Likes
·
0 Votes
·
0 Comments
·
Mark,

Any News ?
·
Tuesday, 25 March 2014 02:36
·
0 Likes
·
0 Votes
·
0 Comments
·
Hi,

Currently this is not the behaviour and we will see if we can add this in the future.
·
Tuesday, 25 March 2014 11:02
·
0 Likes
·
0 Votes
·
0 Comments
·
Hi,

Currently this is not the behaviour and we will see if we can add this in the future.


This is a major security breach.

Thank you
·
Tuesday, 25 March 2014 19:34
·
0 Likes
·
0 Votes
·
0 Comments
·
Hello Cristiano,

I am sorry but I don't really see or understand the problem here. What do you actually mean by changing email and sending activation again? And how would this be a security breach? Can you please elaborate more on this please?
·
Tuesday, 25 March 2014 23:37
·
0 Likes
·
0 Votes
·
0 Comments
·
Hello Cristiano,

I am sorry but I don't really see or understand the problem here. What do you actually mean by changing email and sending activation again? And how would this be a security breach? Can you please elaborate more on this please?


Hello Mark,

sorry for my english

Scenario:

In eaysocial:

A user creates an account. he is asked "Email Account Activation Request".

He clicks on the email activation and can use easysocial.....

The user enter in " edit profile" modifies the original email, inserts a fake or a third party e-mail and will keep using easysocial to spam, and commit crimes etc. ...

The system that allows modification of email without sending a new request for confirmation is contrary to anti spam law in Europe, USA, Brazil.
·
Wednesday, 26 March 2014 04:52
·
0 Likes
·
0 Votes
·
0 Comments
·
Cristiano wrote:

The system that allows modification of email without sending a new request for confirmation is contrary to anti spam law in Europe, USA, Brazil.


That's very new for me "modification of email without sending a new request" (and I'm from Europe and dealing with privacy and law related texts daily).
Could you paste here to which law exactly are you referring to?

Most of the social networks (in US, Europe etc.) are allow to modify the email without require another verification.
·
Wednesday, 26 March 2014 05:06
·
0 Likes
·
0 Votes
·
0 Comments
·
Hello Jozsef Simony,

you can find some references here:

http://www.lsoft.com/resources/optinlaws.asp

Please give it a try and change your email on twitter, facebook, linkedin and others ...
·
Wednesday, 26 March 2014 05:15
·
0 Likes
·
0 Votes
·
0 Comments
·
Cristiano wrote:

you can find some references here:

http://www.lsoft.com/resources/optinlaws.asp

Please give it a try and change your email on twitter, facebook, linkedin and others ...


Dear Cristiano,

These laws are for Marketing Messages. Not for user requested communication. Every user has the option to choose their alert references still...notifications are not marketing messages. It's your responsibility to keep spammers out of your site (you have several tools for that...complex registrations with captcha codes, user-groups, point systems etc.)

I see your point regarding the option to make email change tied to a new verification BUT I'd definitely disable this on my sites.
·
Wednesday, 26 March 2014 05:33
·
0 Likes
·
0 Votes
·
0 Comments
·
I agree with christiano. ..
But, does joomla ask for reactivation or not ?

I would think joomla would implement it if it was that serious security breach.

The whole point of having a valid email address is that the system can email you notifications and such.
·
Wednesday, 26 March 2014 08:17
·
0 Likes
·
0 Votes
·
0 Comments
·
I think you guys are misusing the term "security breach". Security breach simply means that one could bypass the access on the site by performing specific actions. This is merely about changing e-mail address and even Joomla does not do this. A user is allowed to edit their email address even after they have registered.

If your case is about user's changing email, you can simply just disallow users from editing their e-mail address
·
Wednesday, 26 March 2014 11:58
·
0 Likes
·
0 Votes
·
0 Comments
·
View Full Post