|
|
Re: Security IssueFrom: Shawn Hogan Date: Saturday, January 11, 2003
Time: 12:22:56 pmISP List wrote:
> Yes. Customer A knows his login name (joe) but not his password, and puts
> "joe" in the field for password recovery with his correct zip code. Since
> he (joe) has no Override E-mail address or E-mail addresses, OG is assuming
> that "joe@domain.com" is him and it sends that password there, but in
> reality "joe@domain.com" belongs to Customer B.
If "joe" is his login, that's all that is required... it has nothing to do
with override email (as far as searching for the customer)...
It *only* searches against login...
- Shawn
----------------------------------
Shawn D. Hogan
President, Digital Point Solutions
http://www.digitalpoint.com
(858) 452-3696
---------------------------------------------------
To subscribe, unsubscribe or to search list archive
please visit http://www.optigold.com/lists/isp.html
---------------------------------------------------
|

Return to Digital Point Solutions' Home Page |