Anonymous Login

View Issue Details Jump to Notes ]
IDProjectCategoryView StatusLast Update
0000070SKGB-internneues-kennwortpublic2014-07-20 20:45
Reporteraj 
Assigned Toaj 
PrioritynormalSeveritytextReproducibilityalways
StatusresolvedResolutionfixed 
Projectionmajor reworkETAnone 
PlatformWWWOSiCabOS Version3.0b
Product Version1.1Product Build 
Target Version1.2Fixed in Version1.2 
Summary0000070: Change wording to not suggest user failure on neues-kennwort
DescriptionCurrently the copy on neues-kennwort suggests that they forgot the pasword. This isn't very friendly. The text should simply offer to have a new password sent by email, period.
Additional Informationindex.php may have the same issue.

Security Considerations:

By knowing how the password will be delivered, a sophisticated attacker may be able to intercept it and claim the password using the pw-ticket before the legitimate owner does. Since there is no connection-level security before entering digest/, the entire system is vulnerable to a man-in-the-middle attack, possibly actually preventing the reception of the pw-ticket on the legitimate user's end.

The RISK is considered to be low because interception of all emails to a legitimate user by an attack directed at the POP3/IMAP password (or in fact against the digest/ password itself) is easier and more effective.
TagsNo tags attached.
Attached Files

-Relationships
+Relationships

-Notes

~0004909

aj (manager)

The entire copy is /so/ 2004. Replace everything.
+Notes