DVDFile.com  

Go Back   DVDfile.com forum for DVD, Blu-Ray, and HD-DVD > FEATURED DISCUSSION > Bargain Area
Register FAQ Members List Calendar Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
Old 10-09-2004, 06:55 AM   #1 (permalink)
Silent Director/Silent Moderator
 
SilentBob's Avatar
 
Join Date: Feb 2002
Location: Burlington, Ontario
Heads Up for DDD.com Users

Hi everyone.

I have come across a recent thread on the IGN Insiders DVD Board that a possible hack might of happened over at DDD.com site. Many users have reported that their log in has brought them under a different user name several times and can read their (possibly your own) personal info including Credit Card numbers. Some people have been able to get into their account after several tries and suggest changing your info just incase orders/personal id theft may occur.

So far i have been lucky with nothing changing in my account but it might be worth a look just in case.
__________________
SilentBob's DVD's Supporting both HD-DVD and Blu-ray
XBOX LIVE: luvthempocket8s
PS3 ONLINE: pokerlover
SilentBob is offline   Reply With Quote
Old 10-09-2004, 09:19 AM   #2 (permalink)
Wholesome. Actor. Get used to it.
 
mtcarmel00's Avatar
 
Join Date: Nov 2001
Location: San Diego, California
I'd like to get into my account info to delete all my information. If I can't, would you suggest calling the bank to get new card numbers?
__________________
"That could have been your head David."
Clarksville Monkees All-Time Record: 27-27-1
My Photos My DVDs My Blog
mtcarmel00 is offline   Reply With Quote
Old 10-09-2004, 05:25 PM   #3 (permalink)
Producer/Admin
NSFW
Off 'the list'
 
Wirehed's Avatar
 
Join Date: Jul 2001
Location: Sacto, Ca --Near Galt, home of LeVar Burton
Re: Heads Up for DDD.com Users

Quote:
Originally Posted by mtcarmel00
would you suggest calling the bank to get new card numbers?
Yes. That would be in your best interest.
__________________
The Order of the Zombie. The world's greatest zombie culture website.
"Ph'nglui mglw'nafh Cthulhu R'lyeh wagn'nagl dominos"
In his house in R'lyeh, dead Cthulhu waits for the pizza delivery guy.
Wirehed is offline   Reply With Quote
Old 10-10-2004, 12:48 AM   #4 (permalink)
I paid for this!
 
NotaNumber's Avatar
 
Join Date: May 2002
As far as I recall, the account info doesn't show your full CC number. Right now it only shows the last four digits.

I used to use the Private Payments option that American Express was offering (they discountinued this feature recently) which would generate a temporary CC#, good only until the end of the month. This was a very nice feature, but probably was a headache for AMEX.

I did notice the bottom of the Account Info page states:

Quote:
For security reasons, any changes to your account information require that your credit card number to be updated.
This would prevent somebody from changing the email address (account name) and password and placing orders using your CC#.

Thanks for the heads up.
NotaNumber is offline   Reply With Quote
Old 10-10-2004, 07:07 PM   #5 (permalink)
Unique.
Just like the other 768.
 
Icon769's Avatar
 
Join Date: Apr 2002
Location: Southern CA
I heard about this and tried to log in to change my info, it wouldn't let me. After a few tries I finally was able to log in and it looked like nothing had been messed with. I called my credit card company to ask my card be put on hold, after explaining the situation they thought it would be best to cancel, and send me out a new card. DDD fucked up big time, they still leave the site up knowing that this problem is occuring. I don't know if I'll ever order from them again.
__________________
Help me find Dr. Light!
My Collection l Best & Worst Movies
Icon769 is offline   Reply With Quote
Old 10-10-2004, 07:51 PM   #6 (permalink)
Suspended
 
Dilmo's Avatar
 
Join Date: Sep 2002
Location: New Braunfels, Texas. Far From Crawford!
I went in last night and changed my billing to "Bill Me". Whole doing so I saw account information on two different people. I agree that they need to shut the damn site down.
Dilmo is offline   Reply With Quote
Old 10-10-2004, 08:17 PM   #7 (permalink)
Hapless Actor
 
Buffalo Bill's Avatar
 
Join Date: Apr 2002
Location: Walden Puddle.
I thought it was just me and that it was just webtv users. Thursday night I went to DDD 3 times and got 3 different names and secure info for them. Friday night I went to it twice and got called 2 more different names. This time I emailed both of the people from the email addys on their secure page to let them know that DDD is totally fucked up. I called DDD Saturday morning & asked who to talk to about the site not being secure and getting other people's information & was told they were going to shut the site down as they were aware of the problem. Just went there and now my name is Ralph. They obviously haven't fixed it nor is the site shut down for repairs. What a royal fucking mess. Everytime I log out of someone else and log myself in I go to the cart and find something in it not of my doing. They need to do something really fast. This is serious business.
__________________
"Brick Tamland is married with 11 children and is one of the top political advisors to the Bush White House." (now everything makes sense)

"The fundamentals of the economy are sound" John McHoover.
Buffalo Bill is offline   Reply With Quote
Old 10-11-2004, 08:07 AM   #8 (permalink)
Wholesome. Actor. Get used to it.
 
mtcarmel00's Avatar
 
Join Date: Nov 2001
Location: San Diego, California
Re: Heads Up for DDD.com Users

Quote:
Originally Posted by Buffalo Bill
was told they were going to shut the site down as they were aware of the problem. Just went there and now my name is Ralph. They obviously haven't fixed it nor is the site shut down for repairs.
Good to know they were more concerned with enjoying the weekend than protecting the security of their customers.
__________________
"That could have been your head David."
Clarksville Monkees All-Time Record: 27-27-1
My Photos My DVDs My Blog
mtcarmel00 is offline   Reply With Quote
Old 10-11-2004, 05:22 PM   #9 (permalink)
FryMaster
 
limacharliewhiskey's Avatar
 
Join Date: Jun 2002
Location: The O.C.
Just tried to connect to the website, and got a maintenance page. Looks like they're now at work fixing up their shit.
__________________
"Believing oneself to be perfect is often a sign of a delusional mind." - Data in Star Trek: First Contact
DVD Aficionado collection.
limacharliewhiskey is offline   Reply With Quote
Old 10-13-2004, 12:20 AM   #10 (permalink)
Actor
 
Join Date: Jun 2003
Location: Las Vegas
Well if they are fixing it, they aren't doing a very good job about it. I just logged in and all my information has been altered, credit card number, credit card type and expiration date. I removed everything from the site and well had to go ahead and cancel the card.
Lasvegasscott is offline   Reply With Quote
Old 10-13-2004, 12:33 AM   #11 (permalink)
FryMaster
 
limacharliewhiskey's Avatar
 
Join Date: Jun 2002
Location: The O.C.
Well, I just logged into DDD finally, and got in with my correct mailing address and email info. Credit card info seemed to be reset to a generic state, with 0000 as the last 4 digits and an expiration date of 1/04. I switched it to the "Bill Me Later" option.

Don't know if my info was used by anyone else, but I'll keep an eye on my credit card for any unusual activity.

It'll be a long while before I use them again (unless they come up with a 20% off coupon soon ).
__________________
"Believing oneself to be perfect is often a sign of a delusional mind." - Data in Star Trek: First Contact
DVD Aficionado collection.
limacharliewhiskey is offline   Reply With Quote
Old 10-13-2004, 02:42 AM   #12 (permalink)
I paid for this!
 
NotaNumber's Avatar
 
Join Date: May 2002
Well, I logged in over a dozen times since I first saw this thread and never got anybody else's information.

I'd wager this was a database glitch, with the database returning the wrong records on query. Yeah, it happens, even on Apache running ColdFusion with a SQL backend, especially if the indexing tables get scrambled.

I checked my DeepDiscountCD account too and the CC was cleared out. They probably wiped all the CC numbers as a security precaution.
NotaNumber is offline   Reply With Quote
Old 10-13-2004, 11:21 PM   #13 (permalink)
Silent Director/Silent Moderator
 
SilentBob's Avatar
 
Join Date: Feb 2002
Location: Burlington, Ontario
Well my cable modem box crapped oout on me a few days agao and i have been just recently able to get back up and running. It seems the site was hacked into and the person on the IGN Boards that started the thread eventually had someone use his account and try to rack up over $800 in dvd's. Trying to see if anything happened to my account but the log in doesn't seem to really want to log me in. But my banking seems to be ok for my credit card so here's hoping that nothing happened over the past 3 days
__________________
SilentBob's DVD's Supporting both HD-DVD and Blu-ray
XBOX LIVE: luvthempocket8s
PS3 ONLINE: pokerlover
SilentBob is offline   Reply With Quote
Old 10-13-2004, 11:57 PM   #14 (permalink)
Director Emeritus
Persista Persistent Student
 
IKEA_boy's Avatar
 
Join Date: Oct 2001
If I recall, DDD allows you to order without entering your credit card number again. That's what made me nervous. I'd suggest checking your statements online and if you see anything suspicious, call your bank or credit card company.
IKEA_boy is offline   Reply With Quote
Old 10-17-2004, 07:08 PM   #15 (permalink)
Supporting Actor
 
Join Date: Oct 2004
Location: Houston
When I spoke to the DDD.com rep on the phone she said that they just cancelled all the orders from last weekend. I had placed an order, so they gave me a 10% off coupon for my next purchase (for the inconvenience) and reordered what I wanted.
CCollins is offline   Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 10:55 AM.


DVDfile, LLC