Amazon.com Password limit
From: Vishal Ganeriwala (gvishal@ufl.edu)Date: 04/18/02
- Previous message: Frédéric Raynal: "Howto exploit a remote format bug automatically"
- Next in thread: jon schatz: "Re: Amazon.com Password limit"
- Reply: jon schatz: "Re: Amazon.com Password limit"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: 18 Apr 2002 02:24:13 -0000 From: Vishal Ganeriwala <gvishal@ufl.edu> To: bugtraq@securityfocus.com('binary' encoding is not supported, stored as-is)
I found out something in amazon.com . I made a
new account
username : 1abc@a.com
password 12345678
and tried to login with
pasword : 12345678anything
password: 1234567899999999
it lets me login . That means max password lenght
for amazon is 8 chars . It truncts everything after 8
chars. and Amazon doesn't tell you to choose
password of maximum 8 chars . I dont know security
implications . But the information is useful if one is
trying to bruteforce a account since he knows max
password lenght is 8 char .
Vishal .
- Previous message: Frédéric Raynal: "Howto exploit a remote format bug automatically"
- Next in thread: jon schatz: "Re: Amazon.com Password limit"
- Reply: jon schatz: "Re: Amazon.com Password limit"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|
Loading