Bitcoin Forum

Other => Meta => Topic started by: phillipsjk on June 12, 2011, 05:37:56 PM



Title: Can't change my password when logged on via HTTPS
Post by: phillipsjk on June 12, 2011, 05:37:56 PM
As the subject says, I can't change my password when logged on using HTTPS. The system does not accept my old password. I have confirmed my old password still works my logging out then in again.

The problems with sending my password in the clear are obvious.


Title: Re: Can't change my password when logged on via HTTPS
Post by: theymos on June 12, 2011, 08:48:32 PM
Is your password really long? I seem to remember there being a bug with changing super long passwords.


Title: Re: Can't change my password when logged on via HTTPS
Post by: phillipsjk on June 13, 2011, 01:08:22 AM
I have confirmed it happens when I am just using plain HTTP as well.

The password is 10 characters: random numbers, letters and symbols.

The first character is ' (apostrophe/single quote). Is it possible it is not escaped properly in the password verification routine?

To check that I can try resetting my password, I guess.


Title: Re: Can't change my password when logged on via HTTPS
Post by: theymos on June 13, 2011, 01:36:17 AM
Yeah, try resetting your password. That might fix it even if it's something else.


Title: Re: Can't change my password when logged on via HTTPS
Post by: phillipsjk on June 13, 2011, 05:56:29 AM
I have successfully changed my password.

When I made the last post, I got a Database Error. The message had instructions to go back and try again, then reporting the problem (if persistent) to an administrator. Since my message was posted successfully, I did a couple of previews with a string approximately equal to "' ( " in an attempt to reproduce the problem. Shortly thereafter, the website lost its database connection, then it too went down.

It may have been a coincidence due to high server load. However, if I am the one that brought down the server, you have work to do. First, shut-down the server and back up the database ASAP. Second, review Exploits of a Mom (https://xkcd.com/327/). Third, contact me via e-mail for my previous password and the password I was trying to set (both contain "special" characters).


Title: Re: Can't change my password when logged on via HTTPS
Post by: theymos on June 13, 2011, 06:09:48 AM
There were unrelated database problems earlier.