Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Auditing Web Site Authentication, Part One
Mark Burnett

Comments Mode:
Auditing Web Site Authentication, Part One 2008-10-15
Niels
I am wondering how it is safer to reset the password and e-mail a user a lin back to the site than to mail a new (temp) password. If mail is intercepted, than both ways will have the same risk in my opinion? Or am I missing something?

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/infocus/1688/1203#1203







 

Privacy Statement
Copyright 2009, SecurityFocus