diff options
author | David Barksdale <amatus.amongus@gmail.com> | 2012-04-04 21:29:02 -0500 |
---|---|---|
committer | David Barksdale <amatus.amongus@gmail.com> | 2012-04-04 21:30:58 -0500 |
commit | 58d95efffff28e28d4f8db885b7abe7613728740 (patch) | |
tree | 55f6446f173e949ecd2b9732afce3593ff9180dd /src/ctf_website/views/home.clj | |
parent | d2c5278e5995c05949a2bcf431b9b0793b4f0522 (diff) |
Improved new account security.
Since chpasswd takes multiple username:password lines
it was possible to change the password of any account:
curl -data "username=attacker&password=%0aroot:omghax" -k https://ctf/new
Diffstat (limited to 'src/ctf_website/views/home.clj')
0 files changed, 0 insertions, 0 deletions