Tumblr security hole (the gaping kind)
31–40 of 85 posts
Re: Tumblr security hole (the gaping kind)
#32Re: Tumblr security hole (the gaping kind)
#33Probably better to let Tumblr know first, then us. Edit: just confirmed that it works. Basically let's you search users by id or email then give you ability to change their email/reset password.
Ironically they don't obey one of the primary rules of usability for websites: have a link to contact info on the front page.
Re: Tumblr security hole (the gaping kind)
#34Re: Tumblr security hole (the gaping kind)
#35Re: Tumblr security hole (the gaping kind)
#36If that's true, the lead developer should be fired on the spot. They use that "good" old "security by obscurity". I thought this technique was dead long ago....
I can believe they stuck their admin at /admin, but it's hard to believe they didn't create an admin bit as part of the users table and check it to access /admin. That takes about 2 minutes if you do it when you create the system. Oh well, everyone overlooks something that seems obvious to someone else, I guess.