Nicky Vermeersch
Active member
One of my site's members who got his account compromised recently pointed this out to me. As he was going through the email reset form, he noticed that you get two different responses depending on if the email excists or not. He pointed out that this could lead to possible 'email probing / brute force guessing' of email adresses that are registered on the website. This is theorically true, but does this really pose a threat or does Xenforo already has something to prevent this? (like throttling or something)