FlyerTalk Forums - View Single Post - AwardWallet Hack
View Single Post
Old Jul 30, 2015, 3:56 am
  #5  
scibuff
 
Join Date: Jul 2013
Location: BTS
Posts: 611
Oh boy, AW why would you display entered password to loyalty accounts? That is a serious security issue! There is absolutely no need for the user to see the passwords as they can be edited without knowing the current values and you can simply use the values from DB whenever your scripts require them. If an AW user's loyalty account is breached because a hacker looked as the html source where you printed plain text passwords, it is 100% on you!
scibuff is offline