Audiotool board archive

Minor security issue to very very huge ones

anonymous user · started 2022-09-11 21:25 · updated 2022-09-27 04:30

Sorta temporary not an ok thing discovered via experimentation with someone
You can recover anyone's deleted account simply by giving the at team email the url and asking to recover it
In other words
Not sure how they prove owner ship but in my head if you are convincing enough you can actually steal anyone's account.
So yeah we kinda have an issue here

Comments (7)

2022-09-11 21:33 · 2022-09-11

actually just noticed that

2022-09-11 21:35 · 2022-09-11

It's happened before with navor

kurp · reply
2022-09-11 21:35 · 2022-09-11

But I'm not sure how the process works. I assume it's more complicated

anonymous user · reply
2022-09-11 21:36 · 2022-09-11

hmm
seems AT needs to incorporate a 2fa system
Or at least set up a custom security code for signing into an account via new device/ip

anonymous user · reply
2022-09-11 21:40 · 2022-09-11

Im sure they wont just out right hand you someones account even if you say you forgot the email and password
But if its proving yo own it via old tracks or something
People have been backing up accounts via way back, which if you didn't know
Any deleted track if remix is on
Can be remixed and stolen without anyone knowing where you got said track
I've even remixed a track with a deleted account and it appears as co owner
https://www.audiotool.com/track/21el04g9k/
Jungle had deleted their account a year prior yet I was able to make it co owner via this exploit

2022-09-26 16:01 · 2022-09-26

This needs some attention.

anonymous user · reply
2022-09-27 04:30 · 2022-09-27

boink
commenting so it gets sent to the top if it isn't already hopefully the devs saw this