this post was submitted on 26 May 2025
567 points (96.4% liked)

Cybersecurity - Memes

2889 readers
1 users here now

Only the hottest memes in Cybersecurity

founded 2 years ago
MODERATORS
 
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 2 points 2 weeks ago
  1. Aquire password database (it's properly hashed and salted)
  2. Create an account and access the password reset form
  3. Dig into the front-end code to find whatever is doing the hash calculations
  4. Brute-force a list of common passwords and look for matches

It would still take significant time, but it's still a vulnerability, especially as technology evolves. You're right that best practices are different for a reset form, but there are some things that are common (like don't do hashes in the front end).