"Forgot password" hack..

Discussion in 'Security' started by ChelseaFC, Dec 25, 2011.

  1. #1
    Hi Guys,I just wanted to know, because recently I have been hacked. I signed upto a Activeboard forum and stupidly I used the same password as I always do. The Admin then changed the email of my account, sent for a new password and it sent him my current password! No security features whatsoever!I was just wondering if you have ever been caught with this hack, and if you know any other scripts (forums, blogs etc) that do the same.
     
    ChelseaFC, Dec 25, 2011 IP
  2. phpSiteMinder

    phpSiteMinder Peon

    Messages:
    47
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #2
    Proper forgot password systems shouldn't email the current password, but only allow you to choose a new password.
     
    phpSiteMinder, Dec 26, 2011 IP
  3. ChelseaFC

    ChelseaFC Peon

    Messages:
    31
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #3
    Your right, they should do...
     
    ChelseaFC, Dec 27, 2011 IP