Viewing 1 replies (of 1 total)
  • This is new. Obviously there is an exploit or back door that lets someone list the users – probably through sql injection. There must be a plugin that does not sanitize input that does this. Since the password is encrypted they can’t get that, so they run dictionary attacks.

    Keith

Viewing 1 replies (of 1 total)
  • The topic ‘Attacks using registered user IDs’ is closed to new replies.