Search Again:

Re: Security Issue

From: Shawn Hogan
Date: Saturday, January 11, 2003
Time: 12:22:56 pm

ISP List wrote:

> Yes. Customer A knows his login name (joe) but not his password, and puts
> "joe" in the field for password recovery with his correct zip code. Since
> he (joe) has no Override E-mail address or E-mail addresses, OG is assuming
> that "joe@domain.com" is him and it sends that password there, but in
> reality "joe@domain.com" belongs to Customer B.

If "joe" is his login, that's all that is required... it has nothing to do
with override email (as far as searching for the customer)...

It *only* searches against login...

- Shawn

----------------------------------
Shawn D. Hogan
President, Digital Point Solutions
http://www.digitalpoint.com
(858) 452-3696


---------------------------------------------------
To subscribe, unsubscribe or to search list archive
please visit http://www.optigold.com/lists/isp.html
---------------------------------------------------



Messages In This Thread:



Return to Digital Point Solutions' Home Page