Web Wiz - Green Windows Web Hosting - Celebrating 25 Years!

  New Posts New Posts RSS Feed - username and password incorrect hack?
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

username and password incorrect hack?

 Post Reply Post Reply
Author
manster View Drop Down
Newbie
Newbie


Joined: 16 May 2005
Status: Offline
Points: 5
Post Options Post Options   Thanks (0) Thanks(0)   Quote manster Quote  Post ReplyReply Direct Link To This Post Topic: username and password incorrect hack?
    Posted: 04 October 2005 at 9:40pm
I'm having a rather strange login problem. Randomly some user are complaining that they cannot login. They were able to login before perfectly, but all of a sudden some can't. So I have to reset the password for them to get back in. They are getting the message, "sorry, the username or password entered is incorrect."
 
I also tried to do it from another computer and I can't login for them. I have deleted cache and cookies and that did not solve the problem. I have to login as an administrator and change their password to be able to login again. I'm running sql server 2000 on a windows server 2003. I have to do this every now and then for it's very random. And yes I've added the domain to allow cookies.
 
Have I been hacked? I did not have the 7.2 patch. Now I do, and I'm testing.
 
Thanks
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 05 October 2005 at 5:28am
I have had serveral people report recently that people are using the forgotten password feature to change other users passwords.

How the forgotten password fetaure works is to gernerate a new password for the user and email it to them, as passwords are 160bit one way encrypted they can not be recovered so new passowrds have to be generated.

It maybe worth asking your members with this problem to check their email accounts to see if they have a changed password email.

To prevent this problem in future versions I am planning on creating a new system that asks the user when registering to put in a secrete question and aswer, then only send the new password if this question is answered correctly.
Back to Top
manster View Drop Down
Newbie
Newbie


Joined: 16 May 2005
Status: Offline
Points: 5
Post Options Post Options   Thanks (0) Thanks(0)   Quote manster Quote  Post ReplyReply Direct Link To This Post Posted: 05 October 2005 at 12:10pm
Thanks Borg, but I had already read that post. This does not seem to be the issue. The email addresses are fine, because it happened to oney of my usernames as well. I have to reset them to log back in or click forgotten password. Even though, in some cases the forgotten password that is in the email does not work for some users either, this might be another issue as well.
 
Thanks
Back to Top
 Post Reply Post Reply

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.