GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   allinternal and likes privacy breach? (https://gfy.com/showthread.php?t=416273)

mrthumbs 01-13-2005 05:56 PM

allinternal and likes privacy breach?
 
https://secure.perfectgonzo.com/cgi/...t_password.cgi

This system for account retrieval, ive seen other paysites use it, would stop me from joining a site if i knew about it.

media 01-13-2005 05:58 PM

Why would it be a privacy breach???

If someone has your name then they need your email address account info as well...

mrthumbs 01-13-2005 05:59 PM

With the zillions of pornsites around what would be the odds of your victim being a member.. but a last name + email address is too public imo..

Why not last 4 cc digits or the good old "..enter your email address and IF its present in our database..." etc..


Media: exaclty my point email address and lastname .. thats public info.
And those two not only tell me if im a member or not but also displays
my account data and subscriptions.

media 01-13-2005 06:01 PM

Quote:

Originally Posted by mrthumbs
True, with the zillions of pornsites around what would be the odds of your victim being a member.. but a last name + email address is too public imo..

Why not last 4 cc digits or the good old "..enter your email address and IF its present in our database..." etc..

We already have that information anyways on a member.. so why is it considered a privacy breach? I still don't get it... Are you referring to someone just saying lets check if joe blow has an account here? or if my husband is surfing this site? If thats the case, half the ladies will know their husbands account info..

edit: by acount info, I mean cc info

mrthumbs 01-13-2005 06:04 PM

Quote:

Originally Posted by media
Are you referring to someone just saying lets check if joe blow has an account here? or if my husband is surfing this site? If thats the case, half the ladies will know their husbands account info..



If i join a site i dont want anyone except the program owner to know i joined.. i dont want my neighbours checking up on me and see if joined
gaymania.com AND use my account data to leech free porn!!

And my neighours have my lastname + email.. nothing confidential.

media 01-13-2005 06:05 PM

Quote:

Originally Posted by mrthumbs
If i join a site i dont want anyone except the program owner to know i joined.. i dont want my neighbours checking up on me and see if joined
gaymania.com AND use my account data to leech free porn!!

You're not getting the fact that they need to have your email account dude.. the password and login info will be dispatched to an email address which if the person does not know any pass info to this email address to begin with, then they will not be able to get any details on login info..

It will not just say ok heres the details for the random name you entered.. lol

mrthumbs 01-13-2005 06:07 PM

Quote:

Originally Posted by media
You're not getting the fact that they need to have your email account dude.. the password and login info will be dispatched to an email address which if the person does not know any pass info to this email address to begin with, then they will not be able to get any details on login info..

It will not just say ok heres the details for the random name you entered.. lol


Thats my point! Once i fill in lastname + email it displays the username / password data on the webpage.. no email sent.

mrthumbs 01-13-2005 06:09 PM

So basicly to chew it a bit more for my beloved gfy members:

If my neighbours name is John Doe and his emaila ddress is [email protected]
(i got his business card)

i simply enter
DOE and [email protected]

To access his account details.

media 01-13-2005 06:09 PM

Quote:

Originally Posted by mrthumbs
Thats my point! Once i fill in lastname + email it displays the username / password data on the webpage.. no email sent.

So this one will display it right on the page??? Thats insanely stupid.. usually it would send an email to the account holder so they can have the email in their secure password protected account..

if all they require is a name and email to get the pass, then yes this is an insecure form of password lookup..

mrthumbs 01-13-2005 06:10 PM

why use a passowrd system in the first place? just tell your members to login with your lastname + email address!

mrthumbs 01-13-2005 06:11 PM

ARS used to do PW recovery like this a few years back.. they changed it after a few complaints.

s9ann0 01-13-2005 06:25 PM

yea i just broke into a mates account there I am in the members area now :o)

thats shady I like the image verification shit for members access though might have to steal that for my sites

s9ann0 01-13-2005 06:26 PM

urrr they squirting milk up her asshole this site is sick


All times are GMT -7. The time now is 07:50 PM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123