Bugtraq mailing list archives

Amazon.com Password limit


From: Vishal Ganeriwala <gvishal () ufl edu>
Date: 18 Apr 2002 02:24:13 -0000



I found out something in amazon.com  . I made a 
new account 
username : 1abc () a com 
password 12345678
and tried to login  with 
pasword : 12345678anything
password: 1234567899999999
it lets me login . That means max password lenght 
for amazon is 8 chars  . It truncts everything after 8 
chars. and Amazon doesn't tell you to choose 
password of maximum 8 chars .  I dont know security 
implications . But the information is useful if one is 
trying to bruteforce a account since he knows max 
password lenght is 8 char . 

Vishal .


Current thread: