Thread Rating:
  • 1 Vote(s) - 5 Average
  • 1
  • 2
  • 3
  • 4
  • 5
People being hacked since the last Server Check.
happylight Wrote:The login bypass is most likely not related to intrusion of their database at all. Most probably it'd be something akin to adding an email variable to the end of the password reset URL and get the email sent to any account. Some vulnerability on the website would not show up on logs unless you already know what to look for.

Personally I think it's more a matter of just sending the right packets to the server at the right time to make it think the login server approved you, or like the switch hack, to make it think person x is actually person y.

The number of people entered without any changes to the login info is too high for a password reset manipulation to be the only thing out there.
It's not having what you want - It's wanting what you've got.
Reply


Messages In This Thread
People being hacked since the last Server Check. - by Eos - 2011-09-28, 11:19 AM

Forum Jump:


Users browsing this thread: 5 Guest(s)