Disclose.tv doesn't use encryption for logins!

Writer
Posts: 88
Joined: Fri Nov 05, 2010 8:34 pm

You might like:

PostMon Oct 03, 2011 4:47 am » by Koopatroopa


Just a notice for anyone using this website. When you login your username and password are sent unencrypted non-SSL. This means anyone can intercept your password if they are on or inbetween your network and disclose.tv's web server.

To test it out in firefox get FireBug and under the Net tab look for POST requests and you should see /action/login. Your username and password are displayed like that all the way to their webserver.

Who is responsible for system administration cuz at the very least they need to put a SSL cert on the server and setup a rewrite rule to use HTTPS for logins...

Thanks guys.

Super Moderator
User avatar
Posts: 6420
Joined: Fri May 14, 2010 7:03 pm
Location: YOU ALL FLOAT DOWN HERE

PostMon Oct 03, 2011 4:53 am » by Troll2rocks


You know this will cause a shit storm on here right ?

Agreed though.
Image

Writer
Posts: 88
Joined: Fri Nov 05, 2010 8:34 pm

PostMon Oct 03, 2011 4:57 am » by Koopatroopa


troll2rocks wrote:You know this will cause a shit storm on here right ?

Agreed though.


Just doing my part to make sure people's information is secure. I hope someone takes notice and fixes this. It really only takes about an hour to do and I would be happy to instruct anyone that needs the info on how to purchase, request and install an SSL certificate and how to setup the rule to force encryption for logins.

Conspirator
User avatar
Posts: 7529
Joined: Sat May 30, 2009 7:37 am

PostMon Oct 03, 2011 6:31 pm » by Lucidlemondrop


:think:

Initiate
Posts: 473
Joined: Tue Nov 23, 2010 1:21 am

PostMon Oct 03, 2011 7:09 pm » by Eisleo


troll2rocks wrote:You know this will cause a shit storm on here right ?

Agreed though.


Well, on DTV everything turns into a shitstorm, right?

An yes, the site should use SSL!

:flop:
"Kinder, die Zeit ist reif..."

Conspirator
User avatar
Posts: 2053
Joined: Mon Sep 29, 2008 4:23 pm
Location: Orlando, FL

PostMon Oct 03, 2011 7:10 pm » by Kerrblur2


lol yea we spoke about this about 3 years ago when them smurf people were on here. myself along with many other people got together to find one of the smurfs lol we were going to goto his house and vandalize his shit.... so easy to grab peoples personal information on here.

Most under rated
TECH N9ne

Initiate
Posts: 898
Joined: Fri Jul 16, 2010 8:10 pm

PostMon Oct 03, 2011 9:45 pm » by Shemagh


I must get me one of those Internet For Dummies Books, 'cause I havn't a clue what's being talked about here!

Conspirator
User avatar
Posts: 1284
Joined: Tue Oct 26, 2010 4:35 pm

PostMon Oct 03, 2011 9:48 pm » by Poooooot


shemagh wrote:I must get me one of those Internet For Dummies Books, 'cause I havn't a clue what's being talked about here!

lmaooo
You and me both, girl.
Because I'm a lady, ass-wipe!

Super Moderator
User avatar
Posts: 6420
Joined: Fri May 14, 2010 7:03 pm
Location: YOU ALL FLOAT DOWN HERE

PostMon Oct 03, 2011 9:56 pm » by Troll2rocks


shemagh wrote:I must get me one of those Internet For Dummies Books, 'cause I havn't a clue what's being talked about here!



Basically, HTTPS will better protect your identity should anyone care to go a snooping.

Also the certificate has to be paid for but is like insurance to websites of sorts.

It is a mark of guarntee in other words, a guaantee that says, do not try snooping here.

If that makes sense.

However it is all basically a mind game for consumers who think it gives them security when it doesnt really, but its presence being there is basically just a sign to those who might hack/script that it may be better finding other targets. However it is basically nothing more than a sticker in the window in reality saying don't look in here. So it works both ways, those kind of certificates can also make those who are dark hats interested.

In otherwords dammed if you do dammed if you don't.

Welcome to the internet :top:

:cheers:
Image

Initiate
Posts: 898
Joined: Fri Jul 16, 2010 8:10 pm

PostMon Oct 03, 2011 10:16 pm » by Shemagh


troll2rocks wrote:
shemagh wrote:I must get me one of those Internet For Dummies Books, 'cause I havn't a clue what's being talked about here!



Basically, HTTPS will better protect your identity should anyone care to go a snooping.

Also the certificate has to be paid for but is like insurance to websites of sorts.

It is a mark of guarntee in other words, a guaantee that says, do not try snooping here.

If that makes sense.




However it is all basically a mind game for consumers who think it gives them security when it doesnt really, but its presence being there is basically just a sign to those who might hack/script that it may be better finding other targets. However it is basically nothing more than a sticker in the window in reality saying don't look in here. So it works both ways, those kind of certificates can also make those who are dark hats interested.

In otherwords dammed if you do dammed if you don't.

Welcome to the internet :top:

:cheers:









Cheers mate! I think I'll just try to hide amoung the masses!

Next
  • Related topics
    Replies
    Views
    Last post

We are listed at the www.topparanormalsites.com website. Click here to vote for us.. Thank you :-)