I'm going to share to you, all about how I took over hundreds of e-mails and social networking accounts (and counting) all because of a website's security flaw. I e-mailed them about the exploit and reported to them but to no avail, they kept on ignoring me. Maybe because they don't believe me or they think it's nothing serious. I'm expecting this thread to be deleted minutes from now because of the illegal content I'm about to explain.
Now, the worst part is this. All I have to do is guess a password and I can log in to an account complete with e-mail address, password, contact number, address, etc.
How do you feel if someone is snooping around your mail inbox without your consent? Maybe stole a couple of corporate files, read your private messages, doesn't sound good right? Another worst scenario is, you can't delete or cancel your registered account for reasons I do not know, in other words, you're a sitting duck.
Provided by the password, I can log in to your e-mail account, assuming you're using the same password. When I get control of your e-mail, everything else comes tumbling down, that e-mail of yours is used for authentication purposes of your social networking accounts(Facebook, Friendster, Multiply, MySpace, Twitter). Now think about that.
The website I'm talking about is a very popular one. I know majority of you folks here are registered to their online services. I won't name the website for now provided that my threads won't be deleted, an assurance maybe. If I were you, I should be very concerned especially if you like to order books or magazines online. My advice is, never use the same password for all your accounts. Do not take this the wrong way, I'm just using this forum as an outlet because I don't know anymore where to report this kind of news, or how I can reach this company and make them open their eyes.