Security issue: get passwords to every username

Home Page Forums Network Management ZeroTruth Security issue: get passwords to every username

  • This topic is empty.
Viewing 1 post (of 1 total)
  • Author
    Posts
  • #43799
    Simsa
    Member

    Hi, I just noticed when I enter a existing username and any password I get a message “unknown user or unknown password” so far so good, but this message shows the username I entered but ALSO the CORRECT password!

    Is this a general issue or only at my site? And what can I do to avoid this?
    I use Zerotruth 1.0.beta4.

    Edit: For a workaround I deleted in loginerror.sh the two variables $CONTROLUSER and $CONTROLPASSWORD (line 69)

    It seems that truthahn already fixed that, because I downloaded version 1.0.beta4 again and noticed that this two variables are already deleted.

    All buddys who downloaded it before that fix like me, should check this issue at their site.

Viewing 1 post (of 1 total)
  • You must be logged in to reply to this topic.