are webapps allowed to have a default user with a default password?

2008-11-03 Thread Evgeni Golov
Hi *, while working on a fix for opendb's RC/Security bug #504173, I noticed that opendb creates a default admin user "test" with "test" as password. This is IMHO a security hole, but I would like to hear your opinion - is this okay or not? Regards Evgeni -- To UNSUBSCRIBE, email to [EMAIL PRO

Re: are webapps allowed to have a default user with a default password?

2008-11-03 Thread Paul Wise
On Mon, Nov 3, 2008 at 5:40 PM, Evgeni Golov <[EMAIL PROTECTED]> wrote: > while working on a fix for opendb's RC/Security bug #504173, I noticed > that opendb creates a default admin user "test" with "test" as password. > This is IMHO a security hole, but I would like to hear your opinion - > is t

Re: are webapps allowed to have a default user with a default password?

2008-11-03 Thread Evgeni Golov
On Mon, 3 Nov 2008 18:18:38 +0900 Paul Wise wrote: > On Mon, Nov 3, 2008 at 5:40 PM, Evgeni Golov <[EMAIL PROTECTED]> wrote: > > > while working on a fix for opendb's RC/Security bug #504173, I noticed > > that opendb creates a default admin user "test" with "test" as password. > > This is IMHO a