خرید بک لینک

I'm hoping this was the right StackExchange to post in as it's not programming related. Apologies if not.

If I have a user system, be it thin client, web app, software and I have 2 users, Billy and John. Billy and John have the same password out of coincidence, pass1234 but different emails thus:

[email protected] - pass1234

[email protected] - pass1234

If Billy was to accidentally type John's email and login then surely he can login as him; as out of pure coincidence they have the same password.

Are there any programming/system/admin mechanisms to prevent something like this? As what is to stop someone using a fixed password "Passw0rd" and then cycling through thousands of different emails until they get a hit. (excluding the use of captchas)

I'm thinking of something like password + random salt derived from the useame, or hash the password with the useame etc, before verifying at the database level.

برچسب: نویسنده: استخدام کار تاريخ: چهارشنبه 6 مرداد 1395 ساعت: 16:25

صفحه بندی