another stupid kid just hacked my bb.com account

Miscellaneous Forums/General Discussion/another stupid kid just hacked my bb.com account



look at this... i know, this is a security bug, and i know how that works, but please get rid of it. i really dont like "devil GUI LOL"


edit: i will not tell you, how that works. you know why ;)

I wonder why they just changed the GUI entry?

someone loves ya :)

http://www.blitzbasic.com/Contact/_index_.php ?

Anyhow, I never found the worklogs to be setup server-side very well, I mean, from a user point of view it's easy to use and operate, but the underlying coding is messy, the fact you can take any topic and put another users name in it looks bad.
(since it takes in two values from the url, one for the user, one for post)

If this happens so frequently, maybe you should consider revising your own security practices...

Hey... I'm not stupid! Uuhhh, I mean... how do you know the person who did it is stupid?

Hey... I'm not stupid! Uuhhh, I mean... how do you know the person who did it is stupid?

I don't know if thats a hint or a joke.

Pretty sure it's a joke ;)

Sorry to re-open this thread about 'site-security' but I just noticed a thing that BRL's admin site should take in consideration.
If I check my 'Account' page I can see my registered products AND the registration code.
I think it should a better solution if the registration code can be sent (if lost) only by e-mail to the address given at the moment of the registration.
Of course in case of changing e-mail address a contact with BRL will be necessary.
Maybe this is a suggestion already given, in this case I'm late!
Byez

PS: I'm quite sure (well...) that I wrote some other posts in the forum, but now they are gone.

As the sign says, change your password. If you have security concerns please email us.


PS: I'm quite sure (well...) that I wrote some other posts in the forum, but now they are gone.



Moderators on this site have been known to prune topics in order they remain on topic.