Community
Wiki Posts
Search

eService security problem

 
Thread Tools
 
Search this Thread
 
Old Apr 13, 2001 | 3:41 pm
  #1  
Original Poster
Original Member
10 Countries Visited20 Countries Visited30 Countries Visited
 
Join Date: May 1998
Location: SFO/JFK
Programs: Hilton: Diamond, Bonvoy: Lifetime Titanium, Hyatt: Platinum, AS: MVP Gold
Posts: 632
eService security problem

eService is right now letting me view OTHER PEOPLE's itineraries, complete with name, flights and cost. Thankfully, no credit card info is available.

It's not just one person, either ... "My Itineraries" screen shows about 100 itineraries, none of which are mine. I printed out the list and it's about 10 pages worth.

I knew this thing was buggy, but this is inexcusable.
rocky is offline  
Old Apr 13, 2001 | 3:46 pm
  #2  
20 Years on Site
 
Join Date: Nov 2000
Location: DEN / OGG
Programs: Former UA GS, demoted to lowly 1K MM
Posts: 739
Hey, could you fax me a copy of mine? The system is so slow I can't even view my own, let alone other people's!
bikenski is offline  
Old Apr 13, 2001 | 3:54 pm
  #3  
 
Join Date: Oct 2000
Location: Munich, Germany
Programs: LH HON, DL FO/MM, Marriott Lifetime Platinum, Accor Lifetime Platinum, Sixt Diamond
Posts: 6,174
mine works correctly... but such a security problem is a BIG minus.
rcs85551 is offline  
Old Apr 13, 2001 | 4:05 pm
  #4  
 
Join Date: Apr 2001
Location: SFO, Starwood Gold
Posts: 252
Originally posted by bikenski:
Hey, could you fax me a copy of mine? The system is so slow I can't even view my own, let alone other people's!
I don't think there is any point in you trying to look at your itineraries-- CO's web site says old itineraries were *not* transferred to the new site, and I have yet to find anyone who has actually been able to make a reservation on the new site.

This security bug is extremely serious. I will refrain from using the new site even if the speed problem is resolved.


idomoneus is offline  
Old Apr 13, 2001 | 4:05 pm
  #5  
 
Join Date: Apr 2001
Location: SFO, Starwood Gold
Posts: 252
Originally posted by rcs85551:
mine works correctly... but such a security problem is a BIG minus.
Are you viewing itineraries that you made before or after the new site went online?

idomoneus is offline  
Old Apr 13, 2001 | 4:17 pm
  #6  
Original Member
10 Countries Visited
20 Countries Visited
30 Countries Visited
All eyes on you!
 
Join Date: May 1998
Location: Tucson, Southern Arizona, North America, Western Hemisphere, The Earth, a small planet in the solar system. Previously OnePass Infinite Platinum Elite, now over entitled 1K
Posts: 2,293
I tried to look at the itinerary for a flight I booked yesterday, April 12, but the system said that I had "no saved itineraries", even though it said that bookings before April 10 would not be transfered.

I remember some time ago the CO website was showing me other peoples OnePass account balances when I tried to access the "current account balance" feature.

I guess they'll be working overtime tonight.
Old Gold is offline  
Old Apr 13, 2001 | 4:38 pm
  #7  
Suspended
 
Join Date: Mar 2001
Location: FIND ME ON TWITTER FOR THE LATEST
Posts: 27,729
bikenski, LOL.. veeeeery funny!
JonNYC is offline  
Old Apr 14, 2001 | 8:45 pm
  #8  
10 Countries Visited
20 Countries Visited
30 Countries Visited
25 Years on Site
 
Join Date: Feb 2001
Location: Seat 1A or 59B
Posts: 564
I'm getting other peoples itins also, but they appear to be out of CLE only. I was trying to get a price on a ticket, and typed in CLE to BWI. "No such airport or city code: CLE", and the same stuff for BWI. Also changed CLE to Cleveland and so on. Still gives me the nothing found message.

Maybe I should try using my electronic bump voucher issued yesterday...apparently can be used online since all I have is a promo code and a pin. Since when was getting bumped off a flight a promotion?
TimCLE is offline  


Contact Us - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service -

This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2026 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.