Home page logo

funsec logo funsec mailing list archives

How *NOT* to handle incorrect passwords ...
From: "Rob, grandpa of Ryan, Trevor, Devon & Hannah" <rmslade () shaw ca>
Date: Thu, 25 Jul 2013 10:59:55 -0700


Virgin Atlantic feels that it is a good idea to provide the failed password, in plain 
text, in the URL when you try for a reset ...

======================  (quote inserted randomly by Pegasus Mailer)
rslade () vcn bc ca     slade () victoria tc ca     rslade () computercrime org
              Practice random humour and acts of senseless mirth
victoria.tc.ca/techrev/rms.htm http://www.infosecbc.org/links
Fun and Misc security discussion for OT posts.
Note: funsec is a public and open mailing list.

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]