Can you leave feedback for yourself on ebay by changing the URL???? possible loophole/code problem

alkemyst

No Lifer
Feb 13, 2001
83,769
19
81
http://cgi2.ebay.com/aw-cgi/eBayISAPI.dll?LeaveFeedbackShow&useridto=THEIR USERNAME&useridfrom=MY USERNAME&item=the item number

I reversed the two usernames (mine and theirs) to send a link for their feedback to be left....I hit enter by mistake and the form came up for THEM to leave ME feedback...I didn't submit as I am not trying to forge feedback, but does it verify the credentials on the submit?

Something to report to ebay if it doesn't

Å
 

Eli

Super Moderator | Elite Member
Oct 9, 1999
50,419
8
81
Damn...

They need to fix that if its the case.
 

emmpee

Golden Member
Nov 26, 2001
1,100
0
0
i find it hard to believe that it wouldn't authenticate the user via password, but until someone tries it, who knows
 
Oct 19, 2000
17,860
4
81
I would think this would've already been found out, as it is a simple error to make. In eBay's great history, I doubt something this simple has been overlooked for so long.
 

edro

Lifer
Apr 5, 2002
24,326
68
91
Nope, I just tried it and it left him the feedback that I entered in to give myself. It must automatically know and assume it goes to the opposite person.
 

alkemyst

No Lifer
Feb 13, 2001
83,769
19
81
I am doubting it's possible, hence why I am not running screaming to ebay :)....

Do not underestimate the easy hacks, there used to be tons of those.

Edit: thanks for non-confirming (is that a word?) it.

Å
 

edro

Lifer
Apr 5, 2002
24,326
68
91
Wait, I just left a normal feedback the first time. I tried it again on another auction, but got this message:
Invalid Target User ID

Sorry, you cannot leave feedback for yourself. Please go back and enter a different target User ID for your feedback comment.
 

Flyermax2k3

Diamond Member
Mar 1, 2003
3,204
0
0
Originally posted by: alkemyst
I am doubting it's possible, hence why I am not running screaming to ebay :)....

Do not underestimate the easy hacks, there used to be tons of those.

Edit: thanks for non-confirming (is that a word?) it.

Å

why not try it? You won't find out any other way..
 

edro

Lifer
Apr 5, 2002
24,326
68
91
Originally posted by: alkemyst
Are you absolutely sure you had the URL structured properly?

Å

Yes. The first time I had it set to the way you posted and it just left a normal feedback :D I then noticed that I had it the correct way, so I left another feedback (prematurely :)) for another auction and switched the 2, that's when I got that message.
 

alkemyst

No Lifer
Feb 13, 2001
83,769
19
81
Originally posted by: edro13
Originally posted by: alkemyst
Are you absolutely sure you had the URL structured properly?

Å

Yes. The first time I had it set to the way you posted and it just left a normal feedback :D I then noticed that I had it the correct way, so I left another feedback (prematurely :)) for another auction and switched the 2, that's when I got that message.

prematurely as in it didn't end yet or what....

RE: F2M I am not about to risk my own account 'checking' something. I don't have alternate accounts on ebay to perform shenanigans from.

Å
 

RossMAN

Grand Nagus
Feb 24, 2000
79,006
430
136
Originally posted by: alkemyst
Are you absolutely sure you had the URL structured properly?

Å

I've already discovered this and tried using it on a troll who never paid. It does NOT work, it does authenticate with password/cookies/something.

However it is a useful tool. Most eBayers are idiots, so after a transactions I edit the URL so they can simply click it and leave me feedback for a particular auction.