Disclose.tv doesn't use encryption for logins!
14 posts
• Page 1 of 2 • 1, 2
- Koopatroopa

- Posts: 88
- Joined: Fri Nov 05, 2010 8:34 pm
You might like:
Just a notice for anyone using this website. When you login your username and password are sent unencrypted non-SSL. This means anyone can intercept your password if they are on or inbetween your network and disclose.tv's web server.
To test it out in firefox get FireBug and under the Net tab look for POST requests and you should see /action/login. Your username and password are displayed like that all the way to their webserver.
Who is responsible for system administration cuz at the very least they need to put a SSL cert on the server and setup a rewrite rule to use HTTPS for logins...
Thanks guys.
To test it out in firefox get FireBug and under the Net tab look for POST requests and you should see /action/login. Your username and password are displayed like that all the way to their webserver.
Who is responsible for system administration cuz at the very least they need to put a SSL cert on the server and setup a rewrite rule to use HTTPS for logins...
Thanks guys.
- Troll2rocks

-
- Posts: 6420
- Joined: Fri May 14, 2010 7:03 pm
- Location: YOU ALL FLOAT DOWN HERE
You know this will cause a shit storm on here right ?
Agreed though.
Agreed though.

- Koopatroopa

- Posts: 88
- Joined: Fri Nov 05, 2010 8:34 pm
troll2rocks wrote:You know this will cause a shit storm on here right ?
Agreed though.
Just doing my part to make sure people's information is secure. I hope someone takes notice and fixes this. It really only takes about an hour to do and I would be happy to instruct anyone that needs the info on how to purchase, request and install an SSL certificate and how to setup the rule to force encryption for logins.
lol yea we spoke about this about 3 years ago when them smurf people were on here. myself along with many other people got together to find one of the smurfs lol we were going to goto his house and vandalize his shit.... so easy to grab peoples personal information on here.
Most under rated
TECH N9ne
- Troll2rocks

-
- Posts: 6420
- Joined: Fri May 14, 2010 7:03 pm
- Location: YOU ALL FLOAT DOWN HERE
shemagh wrote:I must get me one of those Internet For Dummies Books, 'cause I havn't a clue what's being talked about here!
Basically, HTTPS will better protect your identity should anyone care to go a snooping.
Also the certificate has to be paid for but is like insurance to websites of sorts.
It is a mark of guarntee in other words, a guaantee that says, do not try snooping here.
If that makes sense.
However it is all basically a mind game for consumers who think it gives them security when it doesnt really, but its presence being there is basically just a sign to those who might hack/script that it may be better finding other targets. However it is basically nothing more than a sticker in the window in reality saying don't look in here. So it works both ways, those kind of certificates can also make those who are dark hats interested.
In otherwords dammed if you do dammed if you don't.
Welcome to the internet


troll2rocks wrote:shemagh wrote:I must get me one of those Internet For Dummies Books, 'cause I havn't a clue what's being talked about here!
Basically, HTTPS will better protect your identity should anyone care to go a snooping.
Also the certificate has to be paid for but is like insurance to websites of sorts.
It is a mark of guarntee in other words, a guaantee that says, do not try snooping here.
If that makes sense.
However it is all basically a mind game for consumers who think it gives them security when it doesnt really, but its presence being there is basically just a sign to those who might hack/script that it may be better finding other targets. However it is basically nothing more than a sticker in the window in reality saying don't look in here. So it works both ways, those kind of certificates can also make those who are dark hats interested.
In otherwords dammed if you do dammed if you don't.
Welcome to the internet![]()
Cheers mate! I think I'll just try to hide amoung the masses!
14 posts
• Page 1 of 2 • 1, 2
-
- Related topics
- Replies
- Views
- Last post
-
- WHY DOESN'T MY APPLE MAC DOWNLOAD?
by greys21122012 » Tue Jun 28, 2011 2:38 pm - 4 Replies
- 176 Views
- Last post by hr2burn

Thu Jun 30, 2011 2:32 am
- WHY DOESN'T MY APPLE MAC DOWNLOAD?
-
- Why Doesn't This Site Load Properly While Adblock Plus Is On
by glenn » Fri Jul 09, 2010 3:47 am - 1 Replies
- 94 Views
- Last post by theduck

Fri Jul 09, 2010 10:25 pm
- Why Doesn't This Site Load Properly While Adblock Plus Is On
-
- Why doesn't my avatar photo show up w my posts?
by zengurrl » Fri Feb 18, 2011 10:37 pm - 5 Replies
- 195 Views
- Last post by zaff4444

Sat Feb 19, 2011 12:01 am
- Why doesn't my avatar photo show up w my posts?
-
- what does disclose mean?
1, 2by txrandy68 » Sun Aug 31, 2008 2:09 am - 16 Replies
- 730 Views
- Last post by txrandy68

Tue Sep 02, 2008 12:56 am
- what does disclose mean?
-
- Who Do You Think Is Who on disclose
1 ... 5, 6, 7by darrylmckay » Fri Jul 17, 2009 7:05 am - 67 Replies
- 1076 Views
- Last post by vulcanic

Sat Jul 18, 2009 4:14 am
- Who Do You Think Is Who on disclose










