Results 1 to 9 of 9

Thread: Passwords changing without permission

  1. #1
    samh is offline Here For The Peanuts
    Join Date
    Oct 2009
    Location
    London
    Posts
    193

    Default Passwords changing without permission

    Hi

    Does anyone know of an exploit that changes a user password without permission? Currently I'm notice it change back to their original password

    We're using 3.0.1 - too many plugins to list!

    Cheers for any help

    Sam
    Personally: @srhas Professionally: @FootballUtd

  2. #2
    Jeffro's Avatar
    Jeffro is offline WPTavern Forum Admin
    Join Date
    Jan 2009
    Location
    Ohio
    Posts
    2,359

    Default

    Can't say I've read or heard anything on this. There was an issue back in the 2.8 days where someone could request a users password be changed which was more of an annoyance rather than a security issue.

    http://wordpress.org/news/2009/08/2-...urity-release/

    Doesn't sound related.

  3. #3
    andrea_r's Avatar
    andrea_r is offline WordPress Rockstar
    Join Date
    Jan 2009
    Location
    Eastern Canada
    Posts
    1,325

    Default

    Original passwords aren't stored anywhere though.

  4. #4
    samh is offline Here For The Peanuts
    Join Date
    Oct 2009
    Location
    London
    Posts
    193

    Default

    We have upgraded from 2.8.x to the current version - we went through 2.9 to get there but never actually used 2.9

    So far it's only happened with one user, so we're not panicking just yet....but we don't of course want there to actually be an underlying problem that could affect everyone else
    Personally: @srhas Professionally: @FootballUtd

  5. #5
    andrea_r's Avatar
    andrea_r is offline WordPress Rockstar
    Join Date
    Jan 2009
    Location
    Eastern Canada
    Posts
    1,325

    Default

    If it's one user, I'd be inclined to chalk it up to user error.

    Like I sad above *nothing* stores the original password. If they were mid-way through a password reset, I could see it happening, but again - user error.

    If it happens to another user, then I'd start looking at plugins.

  6. #6
    Jeffro's Avatar
    Jeffro is offline WPTavern Forum Admin
    Join Date
    Jan 2009
    Location
    Ohio
    Posts
    2,359

    Default

    Last night, I received an email that someone requested that my password be changed. In the email sent by WordPress, I had the choice of clicking a link where a new password would be sent or doing nothing which wouldn't have changed my password.

    I didn't request my password to be changed so I ignored the email. However, that's how the process works.

  7. #7
    andrea_r's Avatar
    andrea_r is offline WordPress Rockstar
    Join Date
    Jan 2009
    Location
    Eastern Canada
    Posts
    1,325

    Default

    But from the issue the OP is describing, the OP makes it sound as if that process is actually completed, then at some point, reverts.

  8. #8
    Ipstenu's Avatar
    Ipstenu is offline Big Tipper
    Join Date
    Feb 2010
    Posts
    368

    Default

    Might it be a DB rollback? Is anything else reverting?

  9. #9
    samh is offline Here For The Peanuts
    Join Date
    Oct 2009
    Location
    London
    Posts
    193

    Default

    I'm not aware of anything else reverting Ipstenu - I suppose I could check this by changing my own password and seeing if that ever reverts

    I'll keep you posted! Cheers guys
    Personally: @srhas Professionally: @FootballUtd

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •