View Single Post
  #1  
Old 26th December 2020, 12:42
Elena Elena is offline
Senior Member
 
Join Date: Sep 2010
P2P
Posts: 111
Wink A hole in the registration confirmation system
your website/ok.php?type=signup&email=suslik@gmail.com

your website/confirm.php?id=1&secret=ghjfykjymkuhkuky79mi9ym968 mfm

your website/recover.php?id=1&secret=fghfth67n686u6nu

or a live example:

https://bluebird-hd.org/ok.php?type=...slik@gmail.com

https://bluebird-hd.org/confirm.php?...y79mi9ym968mfm

https://bluebird-hd.org/recover.php?...hfth67n686u6nu



Want to remove the hole? Read here: https://tbdev-forum.top/viewtopic.php?f=53&t=358

Last edited by Elena; 26th December 2020 at 21:32.
Reply With Quote