<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Allison+Nixon</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Allison+Nixon"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Allison_Nixon"/>
		<updated>2026-05-06T09:58:29Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Allison_Nixon&amp;diff=79897</id>
		<title>User:Allison Nixon</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Allison_Nixon&amp;diff=79897"/>
				<updated>2010-03-13T03:22:54Z</updated>
		
		<summary type="html">&lt;p&gt;Allison Nixon: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;I'm joining this website because it seems like an interesting thing to do.&lt;/div&gt;</summary>
		<author><name>Allison Nixon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Allowing_Domains_or_Accounts_to_Expire&amp;diff=79895</id>
		<title>Allowing Domains or Accounts to Expire</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Allowing_Domains_or_Accounts_to_Expire&amp;diff=79895"/>
				<updated>2010-03-13T02:51:57Z</updated>
		
		<summary type="html">&lt;p&gt;Allison Nixon: Created page with '{{Template:Vulnerability}} Last revision (03/12/10): '''{{MAR}}/{{12}}/{{2010}}'''  Vulnerabilities Table of Contents  ==Description==  Through negle…'&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template:Vulnerability}}&lt;br /&gt;
Last revision (03/12/10): '''{{MAR}}/{{12}}/{{2010}}'''&lt;br /&gt;
&lt;br /&gt;
[[ASDR_TOC_Vulnerabilities|Vulnerabilities Table of Contents]]&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
Through neglect an administrator may allow a domain name or e-mail account to expire.  Domains have a significant grace period for expiration, and e-mail addresses using free services such as Yahoo may expire after several months of not logging in.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Risk Factors==&lt;br /&gt;
&lt;br /&gt;
* The biggest risk involved is if you have an e-mail server on a domain that is allowed to expire.  The more users there are, the more personal information you are putting at risk when they use those e-mails as backup e-mails for accounts on websites.  An attacker can simply purchase the domain and setup a mailserver.  By analyzing the spam coming in, they can determine the actual usernames people used on the domain and possibly what services they used with those e-mails.&lt;br /&gt;
* Considering that, you should be careful only to use e-mails hosted on domains owned by companies that don't show any sign of going under in the future.&lt;br /&gt;
* There is very little recourse if a malicious entity has purchased your domain.  They can sell it back to you for however much money they want to charge.  Even if you have grounds for a lawsuit, it can take months at least.&lt;br /&gt;
* If you have applications(especially no-longer supported) sending data to a domain, if an attacker buys the domain they can gather personal information from your users.&lt;br /&gt;
* Domains most likely to expire are those belonging to projects or companies that no longer exist.&lt;/div&gt;</summary>
		<author><name>Allison Nixon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Multiple_admin_levels&amp;diff=79008</id>
		<title>Multiple admin levels</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Multiple_admin_levels&amp;diff=79008"/>
				<updated>2010-02-27T20:20:11Z</updated>
		
		<summary type="html">&lt;p&gt;Allison Nixon: Created page with ' {{Template:Vulnerability}} Last revision (02/27/10): '''{{FEB}}/{{27}}/{{2010}}'''  Vulnerabilities Table of Contents  ==Description==  In an applic…'&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
{{Template:Vulnerability}}&lt;br /&gt;
Last revision (02/27/10): '''{{FEB}}/{{27}}/{{2010}}'''&lt;br /&gt;
&lt;br /&gt;
[[ASDR_TOC_Vulnerabilities|Vulnerabilities Table of Contents]]&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
In an application with administrators that have the ability to alter login credentials of users, if there are multiple levels of administrator permissions, there needs to be a control preventing administrators with lower permission levels from altering login credentials of higher level admins.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Risk Factors==&lt;br /&gt;
&lt;br /&gt;
* Likelihood of this happening relies on an attacker getting control of a lower level admin account in the first place.  &lt;br /&gt;
* Administrator misconduct or mistakes could be made worse if they could easily escalate their own permissions.&lt;br /&gt;
* There is no point to create administrators with different levels of permissions if you don't prevent them from easily escalating their own permissions.&lt;/div&gt;</summary>
		<author><name>Allison Nixon</name></author>	</entry>

	</feed>