5715
posted ago by Doggos [M] ago by Doggos +5721 / -6

u/shadowman3001 and I will respond.

Please DON'T reply to other people's questions before we do. The comment ranking system may cause our replies to get hidden.

Comments (2216)
sorted by:
You're viewing a single comment thread. View all comments, or full comment thread.
4
thegeeseisleese 4 points ago +4 / -0

How can we verify that this redirect is real? Basically what I'm getting at is couldn't the domain owner have built this redirect to a clone site along with identical mod accounts in use by whomever they choose to assign access to the "mod" accounts? With the warnings that this would happen were the site to become compromised, this is suspicious to say the least. Edit: another concern of mine is if the directory structure was also cloned exactly, if the user database is part of the directory, wouldn't that be cloned as well so the usernames would still be associated with their respective passwords? This would allow the old passwords to work, which nullifies the check laid out in an earlier sticky to try a wrong password.

4
Shadowman3001 [M] 4 points ago +4 / -0

The domain owner didn't have access to the user database.

1
thegeeseisleese 1 point ago +1 / -0

If that's the case, then that negates a large concern of mine.