![]() |
![]() |
![]() |
Hyper-ultra-mega-security-bug? I am serious, this was not an hallucination.
Alexandre B. Corrêa
What happens if he changes the password back to the second password (not the original and not what is now)? Can he log in with the original and the second password?
Michael H. Pryor
Unfortunally he has changed this password to a 'third' password... he said we will try to reproduce the problem again (because since he has changed the password the problem is solved).
Alexandre B. Corrêa
Would it be possible for him to email us the first and second password to see if I can run some tests here?
Michael H. Pryor
WE REPRODUCED THE PROBLEM AGAIN.
Alexandre B. Corrêa
We discover the problem: sPassword stored for both passwords is the same, but the passwords are different.
Alexandre B. Corrêa
It seems your routine to cript the password is generating the same string for 'almost-the-same' passwords.
Alexandre B. Corrêa
The funny thing was that this bug was discoverd from OUR testing team. :)
Alexandre B. Corrêa
Yes, you're right... In certain cases two different passwords will hash out to the same string... I'll take a look at beefing this up.
Michael H. Pryor
Folks,
Alexandre B. Corrêa
It is still in the testing phase for the next release. If you are interested in helping us test, please let us know.
Michael H. Pryor
It's out. 3.1.5.
Michael H. Pryor
|