How does the “Forgot Password” function work on the back-end?

292 views

How does the “Forgot Password” function work on the back-end?

In: 135

7 Answers

Anonymous 0 Comments

Some web services invalidate existing auth tokens as soon as a valid email address is used in the password recovery flow rather than when the email link is clicked. You can use this for a mildly inconvenient denial of service attack.

You are viewing 1 out of 7 answers, click here to view all answers.