Web Wiz - Green Windows Web Hosting

  New Posts New Posts RSS Feed - Serious password emailing bug.
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

Serious password emailing bug.

 Post Reply Post Reply
Author
antistar View Drop Down
Newbie
Newbie
Avatar

Joined: 25 June 2003
Status: Offline
Points: 9
Post Options Post Options   Thanks (0) Thanks(0)   Quote antistar Quote  Post ReplyReply Direct Link To This Post Topic: Serious password emailing bug.
    Posted: 24 August 2003 at 7:22am

After running my forum for a couple of months, I decided to set up emailing, so that users could get their passwords emailed to them if they forgot.  To test that it was working, I logged out as administrator, and requested my admin password be sent to me.  This caused an error on line 181 of the password emailing include.  I didn't take a note of the exact error, because I wasn't all that concerned at the time.  It was only when I tried to log back in as administrator that I discovered the problem: it had corrupted my password!

I knew it wasn't because I had forgotten it, because I had a backup of the database running on a different server from only a few days ago, and I could log on to that with the password I knew it to be.  Using the same password on the corrupted forum, resulted in failure.  Thankfully I fixed the problem, by downloading the database and copying a known password (and salt) from a different member whose password I had reset 30 seconds before I had logged out and become locked out.

Having something like that happen is really bad.

Back to Top
God_Struth View Drop Down
Senior Member
Senior Member
Avatar

Joined: 07 August 2003
Location: United Kingdom
Status: Offline
Points: 218
Post Options Post Options   Thanks (0) Thanks(0)   Quote God_Struth Quote  Post ReplyReply Direct Link To This Post Posted: 24 August 2003 at 3:07pm
Did you actually have an email address in your profile when you switched notification on?

Sounds like you didn't.

Back to Top
b_bonnett View Drop Down
Mod Builder Group
Mod Builder Group


Joined: 16 April 2003
Location: New Zealand
Status: Offline
Points: 275
Post Options Post Options   Thanks (0) Thanks(0)   Quote b_bonnett Quote  Post ReplyReply Direct Link To This Post Posted: 24 August 2003 at 5:27pm

Not a bug, since it works fine for me.

It didn't corrupt the database, only did what it was supposed to. Since the passwords cannot be unencrypted, they cannot be sent out, instead they are changed and the new password is sent out. The problem occured because the email function did not work - the password was changed but it couldn't tell you what it was, so you weren't aware of the change. 

This means that the email notification is incorrectly set up. You must have had an email address in your profile, because the function checks the address you entered against the one in the profile. If you want to post the exact details of this error (try recreating it on the backup server - make sure you have friendly errors turned off if you use IE), we'll help you fix it.

Blair



Edited by b_bonnett
Webmaster, The Plane Gallery
Greetings From Christchurch
Back to Top
 Post Reply Post Reply

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.