Okay - this is the third time this has happened to me (not quite a DoS, but it could potentially be one if someone wanted to...). Someone used the "request new password" feature, punching in my user account. It wasn't me - I was gone on a trip. I came home, and my Drupal user account was reset.

It's quite trivial for a malicious user to write a script that harvests user account names off a drupal website, then keeps hitting the "request new password" function for those users.

I would recommend (this is the third time I've posted it) that some sort of personalization control be put into place for a user account - which issues a challenge that must be met, before a password reset is initiated.

I would love to write this up, but I'm not sure how to go about it. Is there anyone out there interested in picking up this challenge? I would consider this a significantly HUGE flaw in Drupal - if all (or most) of the users become locked out of their account because of randomly generated password requests, that would be bad.

Comments

shane’s picture

killes@www.drop.org’s picture

It would really have helped if you had searched the site before filing another issue for that feature...
--
If you have troubles with a particular contrib project, please consider filing a support request. Thanks. And, by the way, Drupal 4.6 will support PHP 5.