Plateforme Level Extreme
Abonnement
Profil corporatif
Produits & Services
Support
Légal
English
Security of Password Recovery
Message
 
 
Information générale
Forum:
ASP.NET
Catégorie:
Autre
Versions des environnements
Environment:
VB 9.0
OS:
Windows Server 2012
Network:
Windows 2008 Server
Database:
MS SQL Server
Application:
Web
Divers
Thread ID:
01612857
Message ID:
01612929
Vues:
52
>Hi,
>
>Speaking about security aspect of Password recovery. Regardless of the approach of resetting password (email password in plain text, or sending a link to reset a password), what if user enters an email that does not exist in the database? Is it ok to return to the user a message such as "Email not found"? In theory someone can check if this or that person has access to the site (by entering an email address) but do you think this may create a security breach?

The very first thing you need to do is create a rescue recovery disc. If your hard drive gets trashed you won't be able to get anywhere without one. I learned this the hard way.
Précédent
Répondre
Fil
Voir

Click here to load this message in the networking platform