3 ms·
Last time I checked, Pinterest is built on Django. They would explicitly need to go out of their way to store password insecurely. Also, the fact that the form
by amccloud 13y ago
Last time I checked, Pinterest is built on Django. They would explicitly need to go out of their way to store password insecurely.
Also, the fact that the form in your screenshot ask for csrf token and session id is very odd.
I'd argue that you found something that wasn't built by Pintest but instead someone's tool for controlling and managing multiple Pinterest accounts.
- est 13y agoDjango by default use salted bcrypt, why would anyone NOT doing that? Adding a change password function to a custom model is too trivial class MyUser(models.Model): password = models.CharField(max_length=128) set_password = django.contrib.auth.models.User.set_password.__func__ check_password = django.contrib.auth.models.User.check_password.__func__ And you can do with your instance with set_password() or check_password() like Django's admin User.