Alimama travel network can retrieve password defects of other users at will and fix them

Source: Internet
Author: User

The random field of the link for retrieving the password of the website is too simple. You can scan the link for other users to retrieve the password and modify the password of the user. Then, you can directly log on to the user account.
Retrieving random password fields is too simple

 


 


By scanning the following fields, you can change the password and log on ..

 


The password retrieval page displays the user's email address.

 

 

Solution:


Increase the intensity of Random Fields for password retrieval. Do not display the user's email address or user name on the password retrieval page.

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.