Sending Messages: Security Issue?
Hi Folks,
do I understand the SDK documentation correctly? As soon as I am identified agains a YIM server, I can use the send message webservice and as little extra, I could use the token "-sendAs" to pretend to be the Queed of England / Caesar of China / President of the USofA / .....?
Is there no need to have certain rights to use that input field?
If so, that would explain a lot of spam I tend getting on YIM. Since some fraudulent party could create an Yahoo Account, get some user-ids, and just start sending messages of any of that user id.
If I read that correctly, that is a huge security hole.
Cheers for enlighting me, if I understood that correctly.
by
3 Replies