Community
Wiki Posts
Search

Really Really Weird! Co.com

 
Thread Tools
 
Search this Thread
 
Old Feb 17, 2011 | 3:49 pm
  #1  
Original Poster
10 Countries Visited
20 Countries Visited
30 Countries Visited
2M
 
Join Date: Oct 2005
Programs: Continental
Posts: 1,662
Really Really Weird! Co.com

I received an email from CO to make sure my ID was in my profile for my upcoming trip.
So I login (not using the link in the email)
and I am looking at my profile, which seems correct.
I check the email settings and notice that there are some strange email addresses in my profile, so I delete them.
I go back to "my account" to look at my upcoming flight to ewr, and click on it...
It says the flight is from IAH-LAX!
Then I notice that now it is not my name on the account, I am logged into someone's account and can view their reservations, and all their personal information!
What is going on?
I saved a screenshot of it and tried to call CO, but I am not going to wait on hold for 20 mins.
hockey7711 is offline  
Old Feb 17, 2011 | 4:01 pm
  #2  
 
Join Date: Nov 2008
Location: SAT / MAA / BOM
Programs: CO Plat; UA 1K; EK Gold
Posts: 5,110
Whoa!

My account seems to be mine currently. Did your problem get "cured"..??
snod08 is offline  
Old Feb 17, 2011 | 4:04 pm
  #3  
Company Representative, United Airlines
 
Join Date: May 2006
Location: Chicago, Houston, or somewhere in between
Posts: 2,176
Originally Posted by hockey7711
I received an email from CO to make sure my ID was in my profile for my upcoming trip.
So I login (not using the link in the email)
and I am looking at my profile, which seems correct.
I check the email settings and notice that there are some strange email addresses in my profile, so I delete them.
I go back to "my account" to look at my upcoming flight to ewr, and click on it...
It says the flight is from IAH-LAX!
Then I notice that now it is not my name on the account, I am logged into someone's account and can view their reservations, and all their personal information!
What is going on?
I saved a screenshot of it and tried to call CO, but I am not going to wait on hold for 20 mins.
Hi hockey7711, please send the screen shot to me at [email protected] and we'll take a look.
UA Insider is offline  
Old Feb 17, 2011 | 4:05 pm
  #4  
Original Poster
10 Countries Visited
20 Countries Visited
30 Countries Visited
2M
 
Join Date: Oct 2005
Programs: Continental
Posts: 1,662
I loged out closed the browser and loged back in, now it is my account.
I was tempted to call the other person to let her know about it, but according to her account she is on LAX right now. (Since I could see it)
It's scary...someone can do some real damage if they were so inclined.
hockey7711 is offline  
Old Feb 17, 2011 | 5:17 pm
  #5  
Original Poster
10 Countries Visited
20 Countries Visited
30 Countries Visited
2M
 
Join Date: Oct 2005
Programs: Continental
Posts: 1,662
Done.
hockey7711 is offline  
Old Feb 17, 2011 | 6:00 pm
  #6  
1M
40 Countries Visited
100 Nights
15 Years on Site
 
Join Date: Jun 2007
Location: DAL
Programs: UA 1K AA EXP Hyatt Globalist Hilton Diamond
Posts: 634
I had the same thing happen to me once a while back. I logged in I noticed I had someone else account. Only reason I knew wasn't my account was the miles. It was an extremely large balance. I was like whoa!!! I hit the jackpot!!! How did I get so many miles?... but then I saw the name and stuff. I was able to go through all their stuff. I logged out and logged back in and it was all back to normal. But it was shocker when I first saw someone else information.
CO777DAL is offline  
Old Feb 17, 2011 | 7:35 pm
  #7  
10 Countries Visited
20 Countries Visited
30 Countries Visited
15 Years on Site
 
Join Date: Dec 2007
Location: PDX|AKL|AMS|GVA|AGP|CPT - or somewhere in between
Programs: DL DM; 2MM
Posts: 2,461
Wink This is really gnarly !

Originally Posted by CO777DAL
I had the same thing happen to me once a while back. I logged in I noticed I had someone else account. Only reason I knew wasn't my account was the miles. It was an extremely large balance. I was like whoa!!! I hit the jackpot!!! How did I get so many miles?... but then I saw the name and stuff. I was able to go through all their stuff. I logged out and logged back in and it was all back to normal. But it was shocker when I first saw someone else information.
I was actually in the process of trying to book some reward tickets on CO.com when I noticed something strange in "my" account - the name on the top was not mine - and tried - kinda embarrassed - to log off/in again and OOPS ... once again entered still another persons's account (better not reveal the name here to avoid shock ) and discovered here on FT that I am currently experiencing this same phenomenon ... but with multiple accounts .. LOL

WHOA .... so many nicely bulging accounts are kinda hard to resist !!!

Last edited by Travelomania; Feb 17, 2011 at 8:35 pm Reason: rephrase
Travelomania is offline  
Old Feb 18, 2011 | 12:31 am
  #8  
A FlyerTalk Posting Legend
10 Countries Visited20 Countries Visited30 Countries Visited20 Years on Site
 
Join Date: Apr 2001
Location: PSM
Posts: 69,232
Wirelessly posted (BlackBerry9630/5.0.0.591 Profile/MIDP-2.1 Configuration/CLDC-1.1 VendorID/105)

Glad to see that the bug with session credentials is still alive.
sbm12 is offline  
Old Feb 18, 2011 | 2:49 am
  #9  
10 Countries Visited
20 Countries Visited
30 Countries Visited
15 Years on Site
 
Join Date: Apr 2007
Location: 42mi from AMS
Programs: UA 1K 1MM, Marriott LT Au, Hilton C, IHG PtA
Posts: 577
Originally Posted by sbm12
Glad to see that the bug with session credentials is still alive.
Or an ISP is playing with transparent proxying again... You'd be surprised how many of those "carrier grade" solutions re-use cookies and session variables...
jupper is offline  
Old Feb 18, 2011 | 3:31 am
  #10  
RNE
 
Join Date: Sep 2005
Location: JZRO
Posts: 9,175
Originally Posted by sbm12
Glad to see that the bug with session credentials is still alive.
I wish the bug that kept me Gold for an extra year would come back. ^
RNE is offline  
Old Feb 18, 2011 | 6:19 am
  #11  
 
Join Date: Jan 2010
Posts: 231
Originally Posted by hockey7711
I received an email from CO to make sure my ID was in my profile for my upcoming trip.
So I login (not using the link in the email)
and I am looking at my profile, which seems correct.
I check the email settings and notice that there are some strange email addresses in my profile, so I delete them.
I go back to "my account" to look at my upcoming flight to ewr, and click on it...
It says the flight is from IAH-LAX!
Then I notice that now it is not my name on the account, I am logged into someone's account and can view their reservations, and all their personal information!
What is going on?
I saved a screenshot of it and tried to call CO, but I am not going to wait on hold for 20 mins.
Sounds like odd.....that means someone can log in my account by accident and could be harmful to my account....
hw807 is offline  


Contact Us - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service -

This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2026 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.