Results 1 to 17 of 17
  1. #1
    penny-slot-machines is offline Private Member
    Join Date
    October 2007
    Location
    London
    Posts
    288
    Thanks
    82
    Thanked 65 Times in 55 Posts

    Default Disturbing security issues at CWC

    I have two security issues with CWC that need addressing

    1) Today, I was sent an email, apparently from CWC - it contained both my login and password. The email came from worldonlinegaming@communicatoremail.com and was a standard marketing email advertising their services

    I had not asked for my login or password to be sent to me

    I feel it is very unsafe to be sent both login and password in a standard marketing email - I should only be sent those details if I request it and the process should be as secure as possible, preferably involving a couple of security questions

    If someone were to access my account, they could get hold of my name, address, phone number and neteller ID - I don't want anyone getting all that information!

    2) Also, I notice that when I login to the CWC affiliate page and click on the 'preferences' panel, it shows my password completely openly, not encrypted in any way whatsoever! There is no reason whatsoever to have a password openly shown like this - If I have logged into my account, then I know my password and it does not need to be openly shown, so that others in my office can see it if they pass by whilst I'm looking at my account

    Anyone else having these or other security issues with CWC?
    .

  2. The Following 2 Users Say Thank You to penny-slot-machines For This Useful Post:

    Daera (30 August 2009)

  3. #2
    universal4's Avatar
    universal4 is offline Forum Administrator
    Join Date
    July 2003
    Location
    Courage is being scared to death...and saddling up anyway. John Wayne
    Posts
    33,881
    Thanks
    4,515
    Thanked 9,270 Times in 5,960 Posts

    Default

    Interesting.

    I agree there shouldn't be any reason to show the password in open text after logging in.

    Are you sure the email that contained your details was not sent by a password request? Maybe someone else performed the request??

    I agree that the only time the password should be emailed from the database is when requested to the original email account on record from a forgot password form.

    Rick
    Universal4
    Gambling World Online Roulette Online Blackjack Live Online Games Sports Betting Horse Racing
    Casino Affiliate Programs
    Hosting and Domain Names
    Gambling Industry Association
    GPWA Moderation by Me and My Big Bad Security Self
    If an affiliate program is not small affiliate friendly (especially small US Affiliate), then they are NOT Affiliate Friendly!

  4. #3
    universal4's Avatar
    universal4 is offline Forum Administrator
    Join Date
    July 2003
    Location
    Courage is being scared to death...and saddling up anyway. John Wayne
    Posts
    33,881
    Thanks
    4,515
    Thanked 9,270 Times in 5,960 Posts

    Default

    Actually, this made me wonder so I took a look around and I didn't even see a forgot password form....

    hmmmm....

    I do see the password in a marketing email as a serious security risk. I mean how many webmasters might unknowingly send this mailing to a prospective sub-affiliate to try and close a sale on a sub signup?

    Martyn, would like your thoughts on this.

    Rick
    Universal4
    Gambling World Online Roulette Online Blackjack Live Online Games Sports Betting Horse Racing
    Casino Affiliate Programs
    Hosting and Domain Names
    Gambling Industry Association
    GPWA Moderation by Me and My Big Bad Security Self
    If an affiliate program is not small affiliate friendly (especially small US Affiliate), then they are NOT Affiliate Friendly!

  5. #4
    penny-slot-machines is offline Private Member
    Join Date
    October 2007
    Location
    London
    Posts
    288
    Thanks
    82
    Thanked 65 Times in 55 Posts

    Default

    Quote Originally Posted by universal4 View Post
    Are you sure the email that contained your details was not sent by a password request? Maybe someone else performed the request??
    Yes, absolutely sure


    This is the from/subject/date information:

    From: worldonlinegaming@communicatoremail.com
    Subject: CWC Affiliate Newsletter
    Date: 28 August 2009 16:48:58 BST




    And this is the content of the email (I've put XXXX in where my details had been placed):

    Hi XXXXXX,

    Please check out our latest newsletter, it has some exciting news regarding the re-launch of one of our brands. Also in this edition:

    Aladdin’s Gold V.2.Awesome
    Budapest Affiliate Conference
    New Creative
    Please follow this link to view all the latest goings on at CWC Affiliates...

    http://www.cwcaffiliates.com/affnews...7/09august.htm

    Your CWC login: XXXXXXXX | Password : XXXXXXXX

    If we can work together on anything else I would love to discuss what options are open to us and help build a successful campaign with CWC Affiliates.

    Regards,
    _______________________________
    Martyn Beacon
    Affiliate Manager | CWC Affiliates.com
    Skype: M8ECO26

    Tel: +44 (0)161 211 1354




    If you do not wish to continue receiving these emails, please Unsubscribe

  6. #5
    penny-slot-machines is offline Private Member
    Join Date
    October 2007
    Location
    London
    Posts
    288
    Thanks
    82
    Thanked 65 Times in 55 Posts

    Default

    By the way, I have emailed Martyn about this, but thought it was important enough to post the details here too, so people can be aware

    Some affiliates may use the same login details for many different accounts, or even for their online banking, who knows?

    You wouldn't want those login details unnkowingly being stored in your computer's email mailboxes - if someone steals your computer they would have access to those password...

  7. #6
    Engineer's Avatar
    Engineer is offline Private Member
    Join Date
    March 2007
    Posts
    524
    Thanks
    488
    Thanked 437 Times in 211 Posts

    Default

    Mainstreet and Jackpot Capital show the password openly, too.

  8. #7
    Anthony-Coral is offline Former Employee of Coral
    Join Date
    September 2008
    Location
    Gibraltar
    Posts
    1,217
    Thanks
    904
    Thanked 717 Times in 443 Posts

    Default

    well I've sent martyn the link to this thread by all the contacts I have for him.

    If there is something that needs fixing there is no doubt he'll do what's required

  9. The Following User Says Thank You to Anthony-Coral For This Useful Post:


  10. #8
    AE-Martyn is offline Former AM
    Join Date
    March 2008
    Location
    Manchester
    Posts
    2,050
    Blog Entries
    3
    Thanks
    637
    Thanked 763 Times in 434 Posts

    Default

    Hi there,

    Thanks for raising this.

    This was an email sent by me pertaining to the affiliate newsletter for this month.

    I included the login information due to the number of lost password requests that I have received recently, I thought it was a decent idea at the time and following these posts and your thoughts on this it will not be done again and I appreciate your concern. However, these same details are sent to you when you sign up in the welcome email, for reference as with most if not all programs.

    As for the password being shown in your account, I will again pass this on to RTG to take action towards showing the password as hidden text.

    Sorry if you feel this is a security breach but it was done in good faith.

    Rick, regards a webmaster sending this on to close a sub deal I think this is highly unlikely as the newsletter which would be sent on is contained on a seperate link which contains NO affiliate data.

    Thanks also to Hodgey for getting in touch to raise this with me late on a Friday evening here in the UK.

  11. #9
    Anthony-Coral is offline Former Employee of Coral
    Join Date
    September 2008
    Location
    Gibraltar
    Posts
    1,217
    Thanks
    904
    Thanked 717 Times in 443 Posts

    Default

    Hey......





    Who loves ya, baby!

  12. #10
    penny-slot-machines is offline Private Member
    Join Date
    October 2007
    Location
    London
    Posts
    288
    Thanks
    82
    Thanked 65 Times in 55 Posts

    Default

    Hi Martyn,

    Thanks for responding to this so quickly, especially on a Friday night!

    Obviously RTG originally intended the password to be displayed as hidden text, because they also provide a "confirm password" box on the same page...

    Cheers again,

    Bill

  13. #11
    AE-Martyn is offline Former AM
    Join Date
    March 2008
    Location
    Manchester
    Posts
    2,050
    Blog Entries
    3
    Thanks
    637
    Thanked 763 Times in 434 Posts

    Default

    Quote Originally Posted by HodgeyBoy View Post
    Hey......





    Who loves ya, baby!
    My mummy....

    Quote Originally Posted by penny-slot-machines View Post
    Hi Martyn,

    Thanks for responding to this so quickly, especially on a Friday night!

    Obviously RTG originally intended the password to be displayed as hidden text, because they also provide a "confirm password" box on the same page...

    Cheers again,

    Bill
    Not a problem, sorry if it caused concern and I hope the cider isnt showing in my posts. Aftryall i tend nit ta drunk whyle workin. *burp*

  14. The Following User Says Thank You to AE-Martyn For This Useful Post:

    TheGamblingGuru (28 August 2009)

  15. #12
    Chalkie's Avatar
    Chalkie is offline Public Member
    Join Date
    December 2008
    Location
    West Bromwich UK
    Posts
    1,991
    Thanks
    683
    Thanked 580 Times in 393 Posts

    Default

    I hope you are a real drinker and have lager with that cider!



    Although i suspect that coming from manchester it is more likely to be a WKD cider drink
    Paul

    [SIGPIC][/SIGPIC]


    GAU - Gambling Afilliates Union


    A lie gets halfway around the world before the truth has a chance to get its pants on.

    Winston Churchill

    Please sign this petition if you live in the UK or are an ex-pat Do not let any more children die for no reason

  16. #13
    penny-slot-machines is offline Private Member
    Join Date
    October 2007
    Location
    London
    Posts
    288
    Thanks
    82
    Thanked 65 Times in 55 Posts

    Default

    How about a pint of real beer, instead of these teenage girl drinks?



  17. #14
    AE-Martyn is offline Former AM
    Join Date
    March 2008
    Location
    Manchester
    Posts
    2,050
    Blog Entries
    3
    Thanks
    637
    Thanked 763 Times in 434 Posts

    Default

    Quote Originally Posted by Chalkie View Post
    I hope you are a real drinker and have lager with that cider!



    Although i suspect that coming from manchester it is more likely to be a WKD cider drink
    Funny you mention the lager, I got a Bud in hand right now.

    And I only stick bottles of WKD to my head...but that is another story!

  18. #15
    Chalkie's Avatar
    Chalkie is offline Public Member
    Join Date
    December 2008
    Location
    West Bromwich UK
    Posts
    1,991
    Thanks
    683
    Thanked 580 Times in 393 Posts

    Default

    Quote Originally Posted by penny-slot-machines View Post
    How about a pint of real beer, instead of these teenage girl drinks?


    I spent a night in a marquee drinking real ale at the Great Orsett Steam Fair years ago, walked out of the marquee to retire to my tent and nearly got squashed by someone equally anebriated driving a steam roller!

    Dangerous stuff that real ale!
    Paul

    [SIGPIC][/SIGPIC]


    GAU - Gambling Afilliates Union


    A lie gets halfway around the world before the truth has a chance to get its pants on.

    Winston Churchill

    Please sign this petition if you live in the UK or are an ex-pat Do not let any more children die for no reason

  19. #16
    universal4's Avatar
    universal4 is offline Forum Administrator
    Join Date
    July 2003
    Location
    Courage is being scared to death...and saddling up anyway. John Wayne
    Posts
    33,881
    Thanks
    4,515
    Thanked 9,270 Times in 5,960 Posts

    Default

    Rick, regards a webmaster sending this on to close a sub deal I think this is highly unlikely as the newsletter which would be sent on is contained on a seperate link which contains NO affiliate data.
    Point taken Martyn, it's just one of those rare "what-if" scenarios that "could" happen.

    But you see, security-wise, that is what a good security auditor tries to think about....the more "what-if's" that are covered the better and safer things can be....

    A healthy discussion none-the-less.

    Rick
    Universal4
    Gambling World Online Roulette Online Blackjack Live Online Games Sports Betting Horse Racing
    Casino Affiliate Programs
    Hosting and Domain Names
    Gambling Industry Association
    GPWA Moderation by Me and My Big Bad Security Self
    If an affiliate program is not small affiliate friendly (especially small US Affiliate), then they are NOT Affiliate Friendly!

  20. The Following User Says Thank You to universal4 For This Useful Post:

    Daera (30 August 2009)

  21. #17
    Daera's Avatar
    Daera is offline Private Member
    Join Date
    May 2005
    Location
    California
    Posts
    511
    Thanks
    1,581
    Thanked 269 Times in 171 Posts

    Default

    Quote Originally Posted by universal4 View Post
    Point taken Martyn, it's just one of those rare "what-if" scenarios that "could" happen.

    But you see, security-wise, that is what a good security auditor tries to think about....the more "what-if's" that are covered the better and safer things can be....

    A healthy discussion none-the-less.

    Rick
    Universal4
    Login names and passwords together, mailed out when not requested is a very big security issue IMO. About a year ago or so, I had 3 of my better affiliate accounts compromised. Somehow someone got access to these 3, changed my Quicktender account to theirs. Changed my email (which was gmail) to theirs (which was gmail). And they almost got my money.

    Thank god I tried to login to Rewards at the end of the month and when my password didn't work I tried the lost password. When it didn't recognize my email address at all in thier system... I freaked.

    Fortune, Rewards and Pantasia had all had this done by the same person. If I had not have been checking stats at the end of the month... I would have really been upset when I got no payment from those 3 programs.

    Security should be really taken seriously with affiliate accounts.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •