Search Again:

Re: Security Issue

From: Mike Bacher
Date: Sunday, January 12, 2003
Time: 1:10:49 pm


>The only way that would do anything "funny" is if the customer that was
>requesting the email set the override email. Not the other way around.
>Customer A can't set their override email to "joe@whatever.com" and then if
>joe (Customer B) requests a password it's not going to do anything because
>it's a different account. The only thing that would be "odd" is if Customer
>A requests their password, it's going to send it to "joe@whatever.com"
>because that's the override email for Customer A. Optigold does not *seach*
>on override email when looking up the customer, it's just where it gets sent
>to when a customer is sent email. And you only can set the override email
>address for your own account.

Customer A has *no* E-mail accounts *or* Override E-mails. OG assumes in
this case that it can send to joe@maindomain.com and it will get to
Customer A. This is a bad assumption. An error or no E-mail at all would
be more appropriate, IMHO.

--Mike


---------------------------------------------------
To subscribe, unsubscribe or to search list archive
please visit http://www.optigold.com/lists/isp.html
---------------------------------------------------



Messages In This Thread:



Return to Digital Point Solutions' Home Page