Control Panel Security Flaw

This is used for general discussion that is not necessarily server-related.
Post Reply
FlyingMongoose
This is my homepage
This is my homepage
Posts: 353
https://www.youtube.com/channel/UC40BgXanDqOYoVCYFDSTfHA
Joined: Fri Sep 17, 2004 7:50 pm
Contact:

Control Panel Security Flaw

Post by FlyingMongoose »

My password is 9 characters long, I accidentally typed in only 8 of the characters, omitting the last. It still logged me in correctly and to the correct account. This seems like a problem to me. I don't know if it applies to a certain number of characters or what, but I see this as a fairly crucial flaw in security. If it's (for some reason) only matching all but the "last character" what if someone has a 6 character password, it would take what? 30 minutes of a brute force password generator to break that because all it needs to have is 5 characters.

Thanks for any kind of prompt response.
Image
User avatar
kraze
Former staff
Former staff
Posts: 4362
Joined: Fri Sep 17, 2010 9:06 am
Location: California

Re: Control Panel Security Flaw

Post by kraze »

Hi,

Are you sure you didn't accidentally hit the correct last number? I attempted to do this multiple times and was unable to duplicate.
@Kraze^NFo> Juski has a very valid point
@Juski> Got my new signature, thanks!
@Kraze^NFo> Out of context!
@Juski> Doesn't matter!
@Juski> You said I had a valid point! You can't take it back now! It's out there!
wyseguy79
A regular
A regular
Posts: 55
Joined: Wed Oct 05, 2011 8:58 pm
Location: Las Vegas, NV

Re: Control Panel Security Flaw

Post by wyseguy79 »

Sounds like auto-complete might have kicked in...
User avatar
Edge100x
Founder
Founder
Posts: 13129
Joined: Thu Apr 18, 2002 11:04 pm
Location: Seattle
Contact:

Re: Control Panel Security Flaw

Post by Edge100x »

If you have an extremely old account (sub-2006 or something like that) and haven't changed your password since that time period, then you may still have an old-style password in the system. If you change/update it, you'll be updated to a type that uses a much more secure hash.

I recommend using a secure password that you change regularly.
Post Reply