This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Forgot Password Cheat Sheet
From OWASP
Introduction
This article provides a simple model to follow when implementing a "forgot password" web application feature.
Steps
1) Gather Identity Data
2) Verify Security Questions
3) Send a Token Over a Side-Channel
4) Allow user to change password
Related Articles
Fishnet Security - | Secure Forgot Password
OWASP Cheat Sheets Project Homepage
Authors and Primary Editors
Jim Manico - jim[at]owasp.org