In a .net application I am working on, In the login page, the passowrd box takes only the first 8 characters to validate. When I enter anything starting from 9th character and I am still successfuly logged in.
It makes no difference if the password is 8 or more characters long. Still I only need to enter first 8 characters right and then I can enter anything want.
1st Example - If the user sets his password to Machine1 - in the login page these passwords are accepted: Machine158, Machine1&5552 etc.
2nd Example - user sets his password to Wonderland-88 (in 'forgotten password' screen) - in the login page these passwords are accepted: Wonderlandy1, Wonderlanguage, Wonderlady-&1a etc.
This is definitely wrong. Only a correct password should be accepted. This is a .aspx page.
Please suggest me where would be the problem for this issue and how can I rectify this..
Thanks in advance.