Quote:
Originally Posted by Darkwaltz4
hmm, this is an interesting hack, but i assume it sends to the same email for every failed attempt
this could reveal to that email the password of one of the mods, who just accidentally mispelled their USERNAME on the login panel.
i dunno, but mods might not enjoy this, and this might be an idea: if a submitted username matches an existing username, then the email of that username is the one who recieves the email  that way the user in question knows they were the one targeted. (and perhaps the 'main' email getting the truly perhaps random attempt notices)
edit: hmm, although that wouldnt fix the whole mispelled name + correct password thing hmm...
truly a touchy subject :-p
edit: furthermore, this cant check if a login attempt worked, but wasnt that user (fully understandable), so this could actually serve to further give out your password :-/
|
I explained the passsord reason in the first post. If the main Admin of your board cannot be trusted with the information if you make a mistake, then you really shouldn't be a Mod there anyway, right?
I think the main Admin should get an email if someone attempts to log in no matter what account is trying to be used. Your idea of sending an email to the username tried is an intersting idea, but only as long as it would be staff personel that had access to whatever CP was trying to be accessed.
How could it further give out your password if they make a successful login? You wouldn't get an email and no information would be sent. If they make a successful login, they would already know your passord. Duh?