[mdlug] TigerDirect admins are clueless

Dave mdlug2 at arb.net
Thu Jul 26 12:13:03 EDT 2007


What a joke.... so, you have to wounder if they keep your password in a 
flat file for "Security" reasons and their latest SQL code chokes on 
special characters...  or they routinely crack their customer's passwords...

Humm, all this on a 7 year old insecure OS.

-dave

Jeff Hanson wrote:
> Dear Jeff Hanson,
>
> In an effort to improve security, we have eliminated certain
> previously allowed characters for use in the creation of a password.
> (Example: > < @ ')
>
> Our records indicated that one or more of these characters were used
> in your password. We have since reset your password.
>
> To retrieve your new password, simply click the link below and enter
> your email address ( jhansonxi at gmail.com ). We will immediately send
> you your new password. You may then update your password in the "My
> Account" page after logging in.
>
> Link to retrieve your new password:
> https://www.tigerdirect.com/cgisec/send_password.asp
>
> -------------------
> Guess what they're running:
> http://searchdns.netcraft.com/?host=tigerdirect.com
> _______________________________________________
> mdlug mailing list
> mdlug at mdlug.org
> http://mdlug.org/mailman/listinfo/mdlug
>   




More information about the mdlug mailing list