Go Back   WarriorForum - Internet Marketing Forums > The Warrior Forum > Main Internet Marketing Discussion Forum
Register Blogs FAQ Social Groups CalendarHelp Desk

Reply
 
LinkBack Thread Tools
Old 09-26-2009, 09:26 PM   #1
Advanced Warrior
War Room Member
 
SharynP's Avatar
 
Join Date: Apr 2006
Location: , , Australia.
Posts: 570
Thanks: 4
Thanked 10 Times in 10 Posts
Default aMember/PayPal Serious Security hole??

I just joined a membership as a 1$ trial. Read the rights that dissallowed me to include in my membership.

So.... I clicked on the "cancel membership" button.
I was taken straight in to my PayPal account to the subscription page to cancel.
I then logged out, clicked the button again and needed to log in.

I really dont know if this is a gap or not, but freaked me out a bit.

We dont log out after any transaction.

Any experts got an idea about this?

Shaz

SharynP is offline   Reply With Quote
Old 09-26-2009, 10:37 PM   #2
Active Warrior
War Room Member
 
cmaclean's Avatar
 
Join Date: May 2009
Location: Vancouver, British Columbia, Canada
Posts: 95
Thanks: 7
Thanked 8 Times in 7 Posts
Social Networking View Member's FaceBook Profile  View Member's Twitter Profile 
Default Re: aMember/PayPal Serious Security hole??

In order to sign up for recurring billing membership when PayPal is the processor, the subscriber must actually have a PayPal account. If you select the credit card option when purchasing, the next page will ask you to choose a password and notify you that a PayPal account has been created.

You can cancel and manage your subscription to that site in your own account.

cmaclean is offline   Reply With Quote
Old 09-27-2009, 12:27 AM   #3
Info Philanthropist
War Room Member
 
tecHead's Avatar
 
Join Date: Jul 2002
Location: USA
Posts: 1,789
Thanks: 383
Thanked 349 Times in 176 Posts
Contact Info
Send a message via MSN to tecHead Send a message via Yahoo to tecHead
Default Re: aMember/PayPal Serious Security hole??

Quote:
Originally Posted by SharynP View Post
I just joined a membership as a 1$ trial. Read the rights that dissallowed me to include in my membership.

So.... I clicked on the "cancel membership" button.
I was taken straight in to my PayPal account to the subscription page to cancel.
I then logged out, clicked the button again and needed to log in.

I really dont know if this is a gap or not, but freaked me out a bit.

We dont log out after any transaction.

Any experts got an idea about this?

Shaz
Hi,

There's really nothing to worry about. PayPal sticks a time limited cookie on your system when you log in, (I think it lasts for like 15min maybe); its safe due to it being over a secure connection, (https://www.paypal.com).

You just clicked the unsubscribe button prior to the cookie timing out; yet you were sent back to PayPal over a secure connection, as well.

The only way this would have been a security risk is if you already had a Trojan, (or similar virus), infecting your machine before you had initiated the transaction.

That particular scenario wouldn't have been PayPal OR the vendor's fault, though.

Hope this helps...
PLP,
tecHead
tecHead is offline   Reply With Quote
Reply

  WarriorForum - Internet Marketing Forums > The Warrior Forum > Main Internet Marketing Discussion Forum

Tags
amember, amember or paypal, hole, security, serious

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



All times are GMT -6. The time now is 12:23 PM.