lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <Pine.NEB.4.53.0305072147570.29219@rhombus.znep.com> From: marcs at znep.com (Marc Slemko) Subject: Hotmail & Passport (.NET Accounts) Vulnerability On Thu, 8 May 2003, Christopher F. Herot wrote: > > I just tried this. It does indeed generate the "reset password" email > and link, which is scary, but following the instructions does not really > reset the password, at least not for the limited test I performed. It definitely worked for me around 20:45 (-0700). Microsoft may have gotten it disabled by now, they do generally have a very quick reaction time to such trivial stupid massive gaping holes once they actually get the message about them.
Powered by blists - more mailing lists