Topics

User Functions

Events

There are no upcoming events

What's New

Stories

No new stories

Comments last 2 weeks


Trackbacks last 2 weeks

No new trackback comments

Links last 2 weeks

No recent new links

NEW FILES last 14 days

No new files

Welcome to Geeklog Wednesday, June 19 2013 @ 07:15 PM EDT


 Forum Index > Support > General Geeklog Support New Topic Post Reply
 Create account without username
   
josheli
 08/20/03 05:59PM (Read 1674 times)  
+----
Newbie

Status: offline


Registered: 08/16/03
Posts: 7
It\'s not that big of a deal, but it seems like a bug. It is possible to register as a new user without a username. I just did it on this site, got an email with a password, and of course can\'t login because I don\'t have a username. But now your database has a few extra records. There needs to be a check added in users.php, createuser(). something like:

if(COM_isEmail($email)) && (isset($username)) {

 
Profile Email Website
 Quote
Robin
 08/21/03 04:07AM  
+++++
Full Member

Status: offline


Registered: 02/15/02
Posts: 725
Further to this, you can actually log in (I did).
When I tried to log in using just a password I was rejected, then I tried to input a space in login field and tadam I was suddenly logged. Strange hmmm.
Does it mean any security issues?

Geeklog Polish Support Team
 
Profile Email Website
 Quote
josheli
 08/21/03 10:58AM  
+----
Newbie

Status: offline


Registered: 08/16/03
Posts: 7
i tried that too, using a space as username to login, but it didn\'t work.

i think it\'s more of a headache than a security problem, and easily fixed.

one possible security problem i can think of is that someone could make a script to bombard you with fake registrations, filling your database with dummy users, and effectively employing a DOS attack.

of course, this can be done even if an empy username wasn\'t allowed, as long as your site accepts instant registrations.

 
Profile Email Website
 Quote
Content generated in: 0.62 seconds
New Topic Post Reply

Normal Topic Normal Topic
Sticky Topic Sticky Topic
Locked Topic Locked Topic
New Post New Post
Sticky Topic W/ New Post Sticky Topic W/ New Post
Locked Topic W/ New Post Locked Topic W/ New Post
View Anonymous Posts 
Able to post 
Filtered HTML Allowed 
Censored Content