[aur-general] No confirmation link received

Evangelos Foutras evangelos at foutrelis.com
Wed Sep 19 18:13:47 EDT 2012


On Thu, Sep 20, 2012 at 1:03 AM, Menachem Moystoviz
<moystovi at g.jct.ac.il> wrote:
> Couldn't you register kuppidon at gmail.com with gmail, and then try
> using the reset password form?
> It should cause the password reset email to be sent to the new account
> - allowing you to use seyz as your username.
>
> Of course, I'm assuming you're legit, since this attack vector is also
> used in cracking attempts in order to enter into old
> accounts - which can allow for social privilege escalation.

"Gmail usernames cannot be recreated after they've been deleted." [1]

:p

[1] https://support.google.com/accounts/bin/answer.py?hl=en&answer=1212172


More information about the aur-general mailing list