Small width layout Medium width layout Maximum width layout Small text Medium text Large text
     Search
Downloads Downloads Directory Directory Forums Forums Forge Forge Blogs Blogs        Marketplace Marketplace Careers Program Careers
Community › Forums Register  |  

Maximum ASP
  Ads  
r2i.ntegrated
 


  Sponsors  

Meet Our Sponsors

Merak Mail Server
WebSecureStores -- ASP.NET & DotNetNuke Hosting Solutions
FCKeditor Project
Salaro -- Skins and more
OnyakTech
The best choice for your web site host, email hosting, and domain registration.
 


DotNetNuke Forums
 
  Forum  DotNetNuke® Pro...  Authentication ...  Password Retrieve - Disable
Previous Previous
 
Next Next
New Post 4/9/2008 9:54 AM
Resolved
User is offline Rob
31 posts
www.clarksmith.biz
10th Ranked


Password Retrieve - Disable 

It seems concerning that a person can request and receive a clear text password for an Active Directory account through the Password Retrieve feature in DNN, and all they need to know is the name of a user account. How is this feature disabled when the AD Provider is installed?

 
New Post 4/9/2008 1:33 PM
User is offline Mike Horton
3163 posts
dnn.gmss.org
4th Ranked






Re: Password Retrieve - Disable 

Because the login control is in a wrapper it's an all or nothing situation (you can't allow it for DNN logins and not allow it for AD logins).  If you open up Admin\Authentication\Login.ascx and change:

 <asp:Linkbutton id="cmdPassword" resourcekey="cmdForgotPassword" cssclass="CommandButton" text="Forgot Password?" runat="server" />

to

 <asp:Linkbutton id="cmdPassword" resourcekey="cmdForgotPassword" cssclass="CommandButton" text="Forgot Password?" runat="server" Visible="false" />

that will stop it from being visible. But note that you'll have to do this on every upgrade of the DNN core files.

 
New Post 4/9/2008 3:14 PM
User is offline Rob
31 posts
www.clarksmith.biz
10th Ranked


Re: Password Retrieve - Disable 

Bummer. Thanks for the method!

 
Previous Previous
 
Next Next
  Forum  DotNetNuke® Pro...  Authentication ...  Password Retrieve - Disable
 


Forum Policy

These Discussion Forums are dedicated to the discussion of the DotNetNuke Web Application Framework.

For the benefit of the community and to protect the integrity of the project, please observe the following posting guidelines:

1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DotNetNuke.
2. Discussion or promotion of DotNetNuke product releases under a different brand name are strictly prohibited.
3. No Flaming or Trolling.
4. No Profanity, Racism, or Prejudice.
5. Site Moderators have the final word on approving/removing a thread or post or comment.
6. English language posting only, please.

 


AfterImage Internet Consulting and SEO Services
AfterImage provides search engine optimization (SEO), Internet consulting and hosting services for the Windows platform (IIS, ASP, SQL Server).
www.afterimage.nl/
Alki Homes - Seattle, WA
Exemplary service for your Seattle Real Estate needs. It's what you deserve from your Realtor®!
www.alkihomes.com
Swanzey Internet Group LLC
DotNetNuke design, development, e-Commerce, hosting, maintenance, and training. Exclusively DotNetNuke.
www.swanzey.com

DotNetNuke Corporation   Terms Of Use  Privacy Statement
DotNetNuke®, DNN®, and the DotNetNuke logo are trademarks of DotNetNuke Corporation
Hosted by MaximumASP