Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

macbookairman

macrumors 6502a
Original poster
Jan 15, 2008
903
11
Nebraska
I'm not sure if this is something people on here know about, but i just discovered that you can access an iDisk file in ALL folders of the iDisk (Not just the Public folder) by typing in this url:

http://www.me.com/ix/username/iDisk/Folder/file
or
http://www.me.com/ix/username/file

I though the only files you could access by URL (and VIEW in the browser, not just download) were files in the public folder. However, you can view non public (private) files with that URL above without having to sign in to an account.

Comments? Is this new news or old news? Is this something that should be fixed (doesn't seem very secure) or is it not a big deal?

Does this work for anybody else?
 

cw2k7

macrumors member
Jan 18, 2008
96
0
That only works if you have previously signed in.

If you have not signed in it will just display a message saying "Unauthorized"

If you have signed in then logged out previously viewed files might still get loaded from the browser cache. But if you refresh the page it will reattempt the download and display the "Unauthorized" message.
 

macbookairman

macrumors 6502a
Original poster
Jan 15, 2008
903
11
Nebraska
how far back does a browsers chache go?

I haven't logged into MobileMe lately, but I'm guessing the cache thing is whats happening.

I guess this thread can be moved to the wasteland...
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.