I have an odd --security vulnerability?-- that I found on Zenpool.
Yesterday I sold one of my accounts with only 2MH of Primes on it. Before selling I:
1. Changed the password to something else
2. Sent the escrow the pass/account name
3. The new buyer then changed it again (presumably) and also changed the email associated with the account.
However, when I go to Zenpool I can log in to that old account with my original password (from before I changed it) that is auto-remembered by the browser. If I attempt to login manually it does not work.
My account is quite small, but some of the accounts selling on the forums are not, so someone could make off with quite a bit of stolen mining, plus liquidate all of the miners on the account and withdraw that total. I would hope that everyone has 2FA enabled on their new account right after they buy it, but even with 2FA I can put all of the miner's a person has up for sale.
I am still able to boost the other accounts miner, put his miners for sale, but not able to withdraw his balance since he has 2FA enabled. I emailed Josh 18 hours ago about this, but no reply.
If you buy an account on hashtalk, you better enable 2FA immediately.
ACCORDING TO ERIC
You have to send them the vulnerability before posting it on here or you won't get paid.
P.S. Thanks for leaving that company!
Not sure how to email Eric, so just emailed Josh. His lack of response seems indicate no one cares.
If someone has Eric's email I can send it to him instead.
Pretty sure this was already dealt with earlier today
"message from cloud by Eric from ZenCloud
Important Message
ZenClouders,
As you may already know, we do not officially support the sale of a ZenCloud account between private parties. However, we know this takes place from time to time therefore the following message is very important.
We've identified a possible vulnerability that would allow an account seller to keep control of the account even after the buyer has changed the password. This would allow the seller to essentially take the account back once it's been sold.
We are working to fix this immediately, but the best course of action is to NOT buy or sell an account from any private party until another announcement is made concerning this issue."