Which error message is better when users entered a wrong password? [closed]

The idea is to not give hackers extra information. If you say wrong password, you’ve told a hacker that they have a correct username, and vice-versa. Although what you’ve said is true, on some sites it is possible to determine if you’ve guessed a username via other means.

Leave a Comment

Hata!: SQLSTATE[HY000] [1045] Access denied for user 'divattrend_liink'@'localhost' (using password: YES)