Print Page | Close Window

Generating new password!!!!

Printed From: Web Wiz Forums
Category: Web Wiz Web App Support Forums
Forum Name: Web Wiz Forums
Forum Description: Support forum for Web Wiz Forums application.
URL: https://forums.webwiz.net/forum_posts.asp?TID=571
Printed Date: 30 March 2026 at 9:48am
Software Version: Web Wiz Forums 12.08 - https://www.webwizforums.com


Topic: Generating new password!!!!
Posted By: klr3
Subject: Generating new password!!!!
Date Posted: 27 February 2003 at 7:58am
I donīt know if you have noticed it but, the "lost password" feature isnīto good at all!

If some one wishes to bug the forum, he could go to the "lost password" feature - reply for new password, by just typing ANY OF THE REG. USERS USERNAMES- and what is the result???

Yes, you are right, all the typed usernames becomes a new password - even though the didnīt apply for it!

So when a user comes back to the forum, he canīt log in, because the password has been regenerated by another user!!!

Sure the users are sendt the new password by mail, but it would keep them from coming back, if the password got changed every 2. day...

Do you think thatīs good?



Replies:
Posted By: WebWiz-Bruce
Date Posted: 27 February 2003 at 8:07am
Anyone got ideas for a better solution???

-------------
https://www.webwiz.net/web-wiz-forums/forum-hosting.htm" rel="nofollow - Web Wiz Forums Hosting
https://www.webwiz.net/web-hosting/windows-web-hosting.htm" rel="nofollow - ASP.NET Web Hosting


Posted By: klr3
Date Posted: 27 February 2003 at 8:11am
Yes, make the database not decryting the passwords!

If users, who download your forum, only would remember to rename the database name, to something else than WWforum.mdb - they wouldnīt have any problems with security!

regards,
kenneth


Posted By: WebWiz-Bruce
Date Posted: 27 February 2003 at 8:32am

Problem is judging by the number of emails accusing me of having an insecure forum code becuase they don't follow this advise that 90% of poeple don't do this.

But I have got another solution, to also ask the user for their email address before sending a new password if the two don't match they don't get sent it.



-------------
https://www.webwiz.net/web-wiz-forums/forum-hosting.htm" rel="nofollow - Web Wiz Forums Hosting
https://www.webwiz.net/web-hosting/windows-web-hosting.htm" rel="nofollow - ASP.NET Web Hosting


Posted By: klr3
Date Posted: 27 February 2003 at 8:41am
The idea isnīt bad at all, as long as users remember to hide the email adress, or admin has actived the built in email client!!!

Regards,
KLR


Posted By: Nigelo
Date Posted: 27 February 2003 at 8:56am

Originally posted by -boRg- -boRg- wrote:

Anyone got ideas for a better solution???

How about 2 additional db fields in Authors table as follows:

1st (encrypted using 1 way PW hashing) = User supplied friendly key word such as Mother's maiden name

2nd (not encrypted) = User supplied prompt for friendly key word such as "My Mother's Name" 

So, User would be required to correctly answer question to regenerate PW. The Admin would not therefore be bothered in majority of cases but in event of complete User brain fade borderiing on lunacy, you could then insist on email from User. The point is that even if DB is hacked, the info is useless in view of hashing.

Bruce, you already have some excellent Technology built - Just re-use for a second level password used as an escape route.

Hope this helps

Take care
Nigel



Posted By: danm
Date Posted: 27 February 2003 at 10:27am

What are the security issues with this procedure for lost password:

-          on the login page the user select ‘lost password’ link

-          enter the user name

-          he will receive the password on the e-mail address stored in his profile

-     next time he will use the user name and the old password received by email



Posted By: djhall
Date Posted: 27 March 2003 at 7:21am

Originally posted by -boRg- -boRg- wrote:

Anyone got ideas for a better solution???

 

How about not changing the password when it is requested?

 



Posted By: WebWiz-Bruce
Date Posted: 27 March 2003 at 9:14am

The new version has another solution, where you also need to type in the users registered email address as well as matching username. This is also how many of boards like phpBB does it.

Passwords can't be retreaved as they are one way 160bit encrypted, so you can't send the old password, a new password must be generated.



-------------
https://www.webwiz.net/web-wiz-forums/forum-hosting.htm" rel="nofollow - Web Wiz Forums Hosting
https://www.webwiz.net/web-hosting/windows-web-hosting.htm" rel="nofollow - ASP.NET Web Hosting



Print Page | Close Window

Forum Software by Web Wiz Forums® version 12.08 - https://www.webwizforums.com
Copyright ©2001-2026 Web Wiz Ltd. - https://www.webwiz.net