PasswordMaker Forums
September 03, 2010, 11:15:20 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
 
   Home   Help Search Login Register  
Pages: [1]
  Print  
Author Topic: Auto-populate false-positive  (Read 2570 times)
breyed
Jr. Member
**
Offline Offline

Posts: 28



WWW
« on: September 15, 2005, 08:11:22 PM »

On the home page for amazon.com, PasswordMaker 0.8.2 is autopopulating the password into the search keyword field.  The result is that the generated password is displayed in plain text in the browser page (and submitted unsecured if you would happen to click Go).

I can't see any explanation for the auto-population.  Here's the HTML for the field that is auto-populated:

Code:
<input type="text" name="field-keywords" size="15">
Logged
Tyrantmizar
Sr. Member
****
Offline Offline

Posts: 307



WWW
« Reply #1 on: September 15, 2005, 09:42:02 PM »

I can't reproduce the auto-populate part, but the fact that it goes to the search field is not good...
Logged
Eric H. Jung
grimholtz
Administrator
*****
Offline Offline

Posts: 3292


WWW
« Reply #2 on: September 15, 2005, 10:11:42 PM »

I'll take a closer look tonight. The algorithm for determining what's a password field (and what's not) completely changed in 0.8.2. I was quite hesitant to do this since the existing algorithm was mature and well-tested (close to a year's use and no complaints). But I saw how the BugMeNot extension was detecting password fields and it looked attractive.

I should have left it alone :(

Sorry for the inconvenience. I will change the algorithm back to the old one ASAP.

-Eric
Logged
Eric H. Jung
grimholtz
Administrator
*****
Offline Offline

Posts: 3292


WWW
« Reply #3 on: September 17, 2005, 12:58:49 AM »

I reproduced the problem on Amazon.com. I've found the problem -- it is with the BugMeNot code. PasswordMaker's previous code works fine.

I'll release a fix tonight.
« Last Edit: September 17, 2005, 12:58:57 AM by Eric H. Jung » Logged
breyed
Jr. Member
**
Offline Offline

Posts: 28



WWW
« Reply #4 on: September 17, 2005, 12:45:12 PM »

Verified fixed in 0.8.3.  I verified on amazon.com plus a non-public site that was exhibiting the same problem.

Thanks for the fix!  :)
Logged
Eric H. Jung
grimholtz
Administrator
*****
Offline Offline

Posts: 3292


WWW
« Reply #5 on: September 17, 2005, 07:07:08 PM »

My pleasure. Thanks for using PasswordMaker.

-Eric
Logged
PasswordMaker Forums
   

 Logged
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC Valid XHTML 1.0! Valid CSS!
anything