|
Original bug/exploit was sent to Sony Online Entertainment December 5th (5 months ago)=0D
They havent fixed it yet.=0D
You can read details here: http://johnhasson.com/blog/archive/2006/05/18/175.aspx=0D
=0D
Summary:=0D
When logging into the forums (tested with the Matrix Online game forums) your sessionid is passed along the URL. And images/etc that link to other websites pass this URL along as the referrer. This URL can be used to log in as that person with out any authentication.=0D
=0D
Lithium has been contacted directly by me about this. I am waiting to hear back from then. SOE was also contacted it has not been fixed (5 months now) but they did say they would "pass it along"=0D
=0D
Forum Link:=0D
https://secure.station.sony.com/login/login/station/login_no_popup.jsp?returnURL=http%3A%2F%2Fmxoboards.station.sony.com%2Fmatrix%2F