Superstar website -...
 

[Closed] Superstar website - wtf is going on?

Posts: 0
Free Member
Topic starter
 

Click on a product - adds to my basket, go to check out and another guys details, and then adds another product when i re-log in!


 
Posted : 15/05/2014 9:30 am
Posts: 17
Free Member
 

see the other thread but I assume you have told them?


 
Posted : 15/05/2014 9:34 am
Posts: 0
Free Member
Topic starter
 

not yet as i have just ordered my parts


 
Posted : 15/05/2014 9:35 am
Posts: 17
Free Member
 

I just posted it on their facebook but I'd assume based on the other thread that other people are currently looking at your account too.


 
Posted : 15/05/2014 9:36 am
Posts: 1048
Free Member
 

Clear any cookies the website has set for a start.


 
Posted : 15/05/2014 9:38 am
Posts: 2596
Full Member
 

I think they've had this problem before haven't they?


 
Posted : 15/05/2014 9:46 am
Posts: 806
Free Member
 

Amazing:

rob jackson - Member
Click on a product - adds to my basket, go to check out and another guys details, and then adds another product when i re-log in!

POSTED 36 MINUTES AGO # REPORT-POST
mikewsmith - Member
see the other thread but I assume you have told them?

POSTED 32 MINUTES AGO # REPORT-POST
rob jackson - Member
not yet as i have just ordered my parts

"I haven't taken the time to speak to the retailer in question but have gone on social media and a forum to spread the allegedly bad news before alerting them to a potential issue and giving reasonable opportunity to resolve it."


 
Posted : 15/05/2014 10:08 am
Posts: 1048
Free Member
 

Ok. Here is what I think is happening.

When you log on to Superstar it tries to set an session cookie. If it can't set a cookie (because you are blocking them), then it puts the session data in the URL as query strings e.g.

With Cookies - http://superstar.tibolts.co.uk/account_history_info.php

becomes:

Without Cookies - http://superstar.tibolts.co.uk/account_history_info.php?order_id=xxxxxxx&osCsid=6x7x8x2xhxmxfxvx2xuxjx5xdx

The osCid is the important part (obviously scrambled in this example).

If someone then posts the second URL on the internet, and a logged in user who is allowing cookies then clicks on that link, they get the page, the server sets a cookie, and they become the user.

I think.

There should be some sort of page state management in their php code to stop this (I am not a developer, so this could be the wrong term).


 
Posted : 15/05/2014 10:22 am
Posts: 0
Free Member
Topic starter
 

andyrm - to stop other users trying to buy in the meantime smart arse whilst i report it


 
Posted : 15/05/2014 10:50 am
Posts: 806
Free Member
 

andyrm - to stop other users trying to buy in the meantime [b]smart arse[/b] whilst i report it

Cheer up mate. No need for that ๐Ÿ™‚ Sun's shining.


 
Posted : 15/05/2014 10:56 am
Posts: 251
Full Member
 

This happened before when the site got busy when they sold off all the KS stuff.

It's a crap design that doesn't scale, basically, I'm not sure it's cookie related as I've had the problem and allow them.

Fruit promised everyone it was fixed after the last time ๐Ÿ™„


 
Posted : 15/05/2014 11:00 am
Posts: 0
Free Member
 

School boy error from the developer. Must be pretty embarrassing for them right now...


 
Posted : 15/05/2014 11:01 am
Posts: 17
Free Member
 

Fruit promised everyone it was fixed after the last time

About what you would expect from their CS/BS and warranty division ๐Ÿ˜‰


 
Posted : 15/05/2014 11:02 am
Posts: 0
Free Member
 

From the OP on this thread that doesn't seem to be the case - he's not clicking through a link to buy something, just using the site.

And that's more concerning because you don't have to have posted a link to anything for your details to be compromised.


 
Posted : 15/05/2014 11:02 am
Posts: 1048
Free Member
 

From the OP on this thread that doesn't seem to be the case - he's not clicking through a link to buy something, just using the site

I suspect he clicked through on the (now removed) link on the chainring thread: http://singletrackworld.com/forum/topic/superstar-narrow-wide-for-those-who-cant-wait


 
Posted : 15/05/2014 11:15 am
Posts: 0
Free Member
Topic starter
 

no i didn't - fresh visit to the site


 
Posted : 15/05/2014 11:17 am
Posts: 7630
Free Member
 

Rob, why are you ordering their shoddy, unreliable, badly made, poor quality, ugly, dangerous tat anyway?

As punishment for that (and for harvesting unsuspecting customer's details on their unsafe, shoddy, ugly, dangerous website) I'm not riding with you until the bits you buy have worn out. In about October.


 
Posted : 15/05/2014 11:22 am
Posts: 0
Free Member
Topic starter
 

was a gift for you ๐Ÿ™


 
Posted : 15/05/2014 11:29 am
Posts: 0
Free Member
 

I think they're just trying to covertly shift more dead stock in your direction.

"Hang on - purple bar ends? I didn't order these! And apparently I paid full price too!"


 
Posted : 15/05/2014 11:39 am
Posts: 2271
Full Member
 

Neil from superstar is still the only person on planet earth I would happily punch.

Do I detect some sexual tension between the two of you ? .... ๐Ÿ˜†


 
Posted : 15/05/2014 11:56 am
Posts: 1048
Free Member
 

no i didn't - fresh visit to the site

I see.

It definitely works though. Just created a test account. If you get the session ID, and that person didn't log off, then you can fill your boots.

Fancy some disk rotors?:

http://superstar.tibolts.co.uk/shopping_cart.php?osCsid=h623khs9aogfbnffm6oevqntn7


 
Posted : 15/05/2014 12:14 pm
Posts: 0
Free Member
 

Thanks, just added a couple of bits to 'your' order. Please let me know when they arrive ๐Ÿ™‚


 
Posted : 15/05/2014 12:37 pm
 Drac
Posts: 50558
 

The only information that seems to be there is the basket information, if try to check the account or proceed to check out it asks you to log in. At least that's what it's done for me when I've tested it.


 
Posted : 15/05/2014 1:52 pm
Posts: 1048
Free Member
 

Someone had logged out the account (which is worrying, because you would hope that would deep six the session).

Try it now.


 
Posted : 15/05/2014 2:01 pm
Posts: 0
Free Member
 

I ordered a set of brake pads once and ended up with 2 pairs of nano tech pedals, result 8)


 
Posted : 15/05/2014 3:43 pm