|
|
 |  |
Re: Security IssueFrom: Shawn Hogan Date: Sunday, January 12, 2003
Time: 10:37:39 amISP List wrote:
> err maybe we aren't talking about the same thing here. I am talking about
> the Password Recovery feature in the Customer Web Interface. If Customer A
> goes to that web page and puts in his login (joe) and his accurate zip
> code, and he has no E-mail addresses or Override E-mail specified inside
> OG, it sends the E-mail with his password to "joe@<main domain>", which
> actually belongs to Customer B.
Correct, which is the same place *any* email is going to go to that customer
(invoices, mass mailing, etc.) Since joe is his login and he has no
override email address, it is going to send to the email address of "joe".
Where would you *want* it to be sent for that customer?
- Shawn
----------------------------------
Shawn D. Hogan
President, Digital Point Solutions
http://www.digitalpoint.com
(858) 452-3696
---------------------------------------------------
To subscribe, unsubscribe or to search list archive
please visit http://www.optigold.com/lists/isp.html
---------------------------------------------------
|

Return to Digital Point Solutions' Home Page |