hello friends, i am a lavalair user. i am using phpthumb, session_start , and htaccess to stop all php extensions in upload sections. // still my users complaining that their ids getting hack.. // hack means somebody changing the passwords of my users. . although he don use to do anything else thn changing password.. // anybody pls help... how, and from where he/she doing it.
anybody faced it before?