Bug reports, feature enhancements or other complaints with the site, with
us or just tell us what a miserable existance you have. No death threats or poetry please. Just kidding, no poetry please.
We should have to type 'old' password to choose a new one.
Date: October 20, 2006 10:28AM
I think you should make it so people would need to put the 'old' password before choosing the new one. The current way isn't it possible to anyone to change my password just by making me see a page like sla.ckers.org/forum/control.php?password=ilovecheese (just an example)
If i'm wrong please tell me why.
ty
Re: We should have to type 'old' password to choose a new one.
Date: October 20, 2006 06:22PM
well for the sake of the long term.. it's probably worth adding a current pass check. Not that i'm worried anyone here would try to change my password _-_
Just because car theft is illegal, doesn't mean it's wise to leave them unlocked ..
-maluc
Re: We should have to type 'old' password to choose a new one.
Date: October 23, 2006 08:53AM
I did not check, but I'm pretty sure it works. My bet is that rsnake was aware of it for a long time, but believed everyone here will obey the rules ;)
Re: We should have to type 'old' password to choose a new one.
Date: October 24, 2006 01:10PM
I'm preaty sure you can fix this single "bug" in 5 minutes rsnake but it also should work for email/sig changing, posting etc. So there should be a random identifier for the user session required for every action :F
Someone could do this: make it pm the "hacker" with something so he knows who he has owned, and also change the person email to something so the other person can't retrieve the password :w00t:
--
http://chasenet.org/home/
Re: We should have to type 'old' password to choose a new one.
Date: January 23, 2009 03:06PM
At one point I bought a SSL Cert for this domain, but I forget where I put it...someday, when I get a sysadmin to do shit like that I'll make sla.ckers SSL...
-id
Re: We should have to type 'old' password to choose a new one.
Date: May 07, 2009 12:35PM
CSRF? hey check out this blog, (and turn off ur no script) and ignore my hidden iframe to change ur password
i dont know if slackers has csrf protection as i havent tried messing around
so if they do ignore my ramblings
http://www.xssed.com/archive/author=PaPPy/
Re: We should have to type 'old' password to choose a new one.
Date: June 08, 2009 10:26PM
Trust is a funny thing...
I trust most of you. I don't ask the same back, not that I could do anything.
--
Can you hear them?
So much to learn, so little time...