[Dshield] seems like a flaw in a yahoo url

Andy Streule andy.streule at lythamhigh.lancs.sch.uk
Fri Apr 23 13:53:43 GMT 2004


>This is a very common technique, and somewhat hard to prevent. 
>Most login systems will block an account, if you attempt a bad
>password more then n times. However, if you don't care which
>account you are going to crack, you just use a commonly used
>password, and try different userids. 

some login systems dont put the login details in a url tho. those
systems are safer arent they?

where does that url i spotted come from anyway?

~Andy


***************************************************************************
This e-mail is confidential and privileged.  If you are not the intended
recipient do not disclose, copy or distribute information in this e-mail
or take any action in reliance on its content.
***************************************************************************

***************************************************************************
This email has been checked for known viruses. 
***************************************************************************



More information about the list mailing list