Temporary passwords must expire within a suitably short time period. Enforce the changing of temporary passwords on the next use - no user should be utilising a temporary password on a regular or ongoing basis.
Sven can reuse a temporary password because the user does not have to change it on first use, or it has too long or no expiry, or it does not use an out-of-band delivery method (e.g. post, mobile app, SMS)
Owasp ASVS (4.0): 2.5.6
Capec: 50
Owasp SCP: 37,45,46,178
Owasp Appsensor:
Safecode: 28
ASVS V2.5 - Credential Recovery Requirements
Password Guessing/Brute Force Attacks
Account Takeover (ATO) Attacks
Loading comments 0%