Skip to content
This repository has been archived by the owner on Aug 16, 2019. It is now read-only.

auth token #515

Open
ghost opened this issue Oct 16, 2012 · 0 comments
Open

auth token #515

ghost opened this issue Oct 16, 2012 · 0 comments

Comments

@ghost
Copy link

ghost commented Oct 16, 2012

Once an auth token is stolen - which is sent in cleartext via a GET request in some cases (reset.php for instance) - an account is permanently compromised. Any attacker can visit isense's reset.php with a stolen auth key and reset the password of the targeted user.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

0 participants