473,811 Members | 3,640 Online
Bytes | Software Development & Data Engineering Community
+ Post

Home Posts Topics Members FAQ

Harrassment Using the Password Recovery Control

When the password is hashed and most secure this control mails a new
password to anybody that provides an authenticated user name. The previous
password can no longer be used to login. The newly "recovered" password must
be used to login and then the user must change the newly generated password
back to what may be a preferred password.

Know anybody you want to harrass? Simply enter their user name into an
ASP.NET 2.0 Password Recovery control.
<%= Clinton Gallagher
NET csgallagher AT metromilwaukee. com
URL http://www.metromilwaukee.com/clintongallagher/
May 20 '06 #1
4 1884

When the password is hashed and most secure this control mails a new
password to anybody that provides an authenticated user name. The previous
password can no longer be used to login. The newly "recovered" password must
be used to login and then the user must change the newly generated password
back to what may be a preferred password.

Know anybody you want to harrass? Simply enter their user name into an
ASP.NET 2.0 Password Recovery control.
<%= Clinton Gallagher


And this makes it different from 99% of all known 'Forgotten your password?'
promts on the web in which way?

--
Simon
May 20 '06 #2
This is where secret question/answer combination helps. User must know
secret answer too

I hope this helps
Galin Iliev[MCSD.NET]
www.galcho.com

May 20 '06 #3

This is where secret question/answer combination helps. User must know
secret answer too

I hope this helps
Galin Iliev[MCSD.NET]
www.galcho.com

OK, I apologize: it's not 99%, it's 90%.

--
Simon

BTW - if you quoted messages you answer, people might know what you're
talking about. I just took a swag that you were answering my earlier reply.
Since you didn't provide a secret question/answer combination then this
May 20 '06 #4
It looks that way doesn't it? But I wonder how many have or are implementing
that template.

<%= Clinton Gallagher
NET csgallagher AT metromilwaukee. com
URL http://www.metromilwaukee.com/clintongallagher/
"Galcho[MCSD.NET]" <ga****@gmail.c om> wrote in message
news:11******** **************@ 38g2000cwa.goog legroups.com...
This is where secret question/answer combination helps. User must know
secret answer too

I hope this helps
Galin Iliev[MCSD.NET]
www.galcho.com

May 20 '06 #5

This thread has been closed and replies have been disabled. Please start a new discussion.

Similar topics

0
2112
by: com | last post by:
MS Access 2000 Password Recoverer 4.2 Screenshot - Soft30.com MS Access 2000 Password Recoverer will display the password to a MS Access database (*.mdb). This program works for MS Access files saved in MS Access 2000. ... www.soft30.com/screen-149-12232.htm - 32k - Cached - Similar pages MS Access HTML Help Generator 1.2 - Soft.com MS Access HTML Help Generator 1.2. ... System Requirements: MS Access 2000 / XP /
0
2030
by: =?Utf-8?B?am1obWFpbmU=?= | last post by:
I'm trying to create a process that allows me to limit the non-alphanumeric characters generated with the PasswordRecovery control. Specially I want to suppress some characters for security reasons. With textboxes I'm doing this with a RegularExpressionValidator control and have the following the following attribute setup: ValidationExpression="^{6,100}" This limits the user input to alphanumeric characters as well of some selected...
0
1066
by: xke | last post by:
Having a Login Control on my page caused an issue when press enter (after filling out username and pwd fields). I manage to get through by setting the default button for the page form: mainForm.DefaultButton = loginbtn.UniqueID. My problem is now with Password Recovery. Password Recovery is a bit complicated because it's two parts process. I want to have the same behaviour, press enter same as click on the button.
1
1796
by: Rusty Hill | last post by:
I am using the ASP.NET 2.0 Login control and have provided a valid URL for the PasswordRecoveryURL property. However when the hyperlink is selected the login page continues to be displayed. The URL I start with at the login page is this: http://localhost:1123/MyBox/Unsecured/Login.aspx?ReturnUrl=%2fMyBox%2fDefault.aspx The URL on the login page for the password recovery control shows up as: .../Public/RecoverPassword.aspx which seems...
1
1418
by: Me LK | last post by:
Unfortunately I am working on a site that started awhile ago in 1.1 and is just now being finished. This means I don't have all the features of 2.0 like the password controls. I am looking for some sample code or ideas for implementing password recovery. The passwords are hashed so I can not send the password to the user. Does anyone have any good examples. I did do a Google search but I am bombarded with 2.0 samples which just makes me...
1
1464
by: crystalvista | last post by:
When i m using password recovery control there is an error like System.Net.Sockets.SocketException: No connection could be made because the target machine actively refused it and not able to send new password to email id. but if i use simple smtp.sendmail on buttion click this would work.
2
1714
by: whitey | last post by:
Hi All, The following script works when username(or email) and password are in 1 table. what i need to know is how to adjust the code to reflect that the email will be held in tbl_email and the password will be held in tbl_master_name. <?php include ("conn.inc.php");
1
1600
by: John | last post by:
Hi How can I assign an SMTP server to password recovery control? Thanks Regards
1
1360
by: =?Utf-8?B?SHVzYW0=?= | last post by:
Hi : I have the following code that I used it in password recovery: Dim mail As New MailMessage() mail.From = New MailAddress("husam_108@yahoo.com") mail.To.Add("husamalahmadi@hotmail.com") mail.Subject = "The password" mail.Body = "you password is: " + password Dim smtp As New SmtpClient("127.0.0.1", 25) smtp.Send(mail)
0
9726
marktang
by: marktang | last post by:
ONU (Optical Network Unit) is one of the key components for providing high-speed Internet services. Its primary function is to act as an endpoint device located at the user's premises. However, people are often confused as to whether an ONU can Work As a Router. In this blog post, we’ll explore What is ONU, What Is Router, ONU & Router’s main usage, and What is the difference between ONU and Router. Let’s take a closer look ! Part I. Meaning of...
0
10647
Oralloy
by: Oralloy | last post by:
Hello folks, I am unable to find appropriate documentation on the type promotion of bit-fields when using the generalised comparison operator "<=>". The problem is that using the GNU compilers, it seems that the internal comparison operator "<=>" tries to promote arguments from unsigned to signed. This is as boiled down as I can make it. Here is my compilation command: g++-12 -std=c++20 -Wnarrowing bit_field.cpp Here is the code in...
1
10395
by: Hystou | last post by:
Overview: Windows 11 and 10 have less user interface control over operating system update behaviour than previous versions of Windows. In Windows 11 and 10, there is no way to turn off the Windows Update option using the Control Panel or Settings app; it automatically checks for updates and installs any it finds, whether you like it or not. For most users, this new feature is actually very convenient. If you want to control the update process,...
0
10130
tracyyun
by: tracyyun | last post by:
Dear forum friends, With the development of smart home technology, a variety of wireless communication protocols have appeared on the market, such as Zigbee, Z-Wave, Wi-Fi, Bluetooth, etc. Each protocol has its own unique characteristics and advantages, but as a user who is planning to build a smart home system, I am a bit confused by the choice of these technologies. I'm particularly interested in Zigbee because I've heard it does some...
0
9204
agi2029
by: agi2029 | last post by:
Let's talk about the concept of autonomous AI software engineers and no-code agents. These AIs are designed to manage the entire lifecycle of a software development project—planning, coding, testing, and deployment—without human intervention. Imagine an AI that can take a project description, break it down, write the code, debug it, and then launch it, all on its own.... Now, this would greatly impact the work of software developers. The idea...
1
7667
isladogs
by: isladogs | last post by:
The next Access Europe User Group meeting will be on Wednesday 1 May 2024 starting at 18:00 UK time (6PM UTC+1) and finishing by 19:30 (7.30PM). In this session, we are pleased to welcome a new presenter, Adolph Dupré who will be discussing some powerful techniques for using class modules. He will explain when you may want to use classes instead of User Defined Types (UDT). For example, to manage the data in unbound forms. Adolph will...
0
6887
by: conductexam | last post by:
I have .net C# application in which I am extracting data from word file and save it in database particularly. To store word all data as it is I am converting the whole word file firstly in HTML and then checking html paragraph one by one. At the time of converting from word file to html my equations which are in the word document file was convert into image. Globals.ThisAddIn.Application.ActiveDocument.Select();...
0
5692
by: adsilva | last post by:
A Windows Forms form does not have the event Unload, like VB6. What one acts like?
1
4338
by: 6302768590 | last post by:
Hai team i want code for transfer the data from one system to another through IP address by using C# our system has to for every 5mins then we have to update the data what the data is updated we have to send another system

By using Bytes.com and it's services, you agree to our Privacy Policy and Terms of Use.

To disable or enable advertisements and analytics tracking please visit the manage ads & tracking page.