Bitcoin Forum
May 30, 2024, 05:43:20 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: A method to recover auto-locked account in MPOS pool  (Read 652 times)
shimonkobi (OP)
Newbie
*
Offline Offline

Activity: 3
Merit: 0


View Profile
March 06, 2014, 12:48:18 AM
 #1

A method to recover an auto locked account by a pool. (you had supposed to receive an unlock email)
But if you didn't receive this email then request a password reset and Don't click the link! then take the token form link and the domain. And put them in an unlock link.

This works because the token is like a cookie. a cookie in user's account database record. the record is updated each time to a different random value, and deleted after use. The reason it fails because there is only one column for token for all the commands. This is kind of an insignificant security weakness witch can be exploited to your advantage to recover your account.

Example unlock address I got once from a MPOS pool:

http://domain.com/index.php?page=account&action=unlock&token=2c24abed528203fbc56f58bae761c2c4cb171eeb31f62e6963c458d3747bba00

Shimon Doodkin

Send to me some of the recovered money:

bitcoin: 1Gc1wwgSg3sSEKrEwhmvbsgRWcKRJHrv5d
auroracoin: Af5RYDkFjG4DDjLkjEZ24gpmbxyEw2b7zQ
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!