Recommended Posts

So reading a thread and came across this statement

"Even the neowin login page is not encrypted"

Now I thought to myself - that can not be true.. I know the page itself is not fully encrypted, but that is not an issue the sending of the username and password could be using a https post, etc.

So figured I would take a look see.... Oddly enough, the post for the login looks to be in the clear from the page source

    <form action="https://www.neowin.net/forum/index.php?app=core&module=global&section=login&do=process" method="post" id='login'>

Now I said -- hmmm, I know a little bit about html, but maybe I am missing something and I am looking at it wrong or something. So I did what I know better and that is looking at network sniffs... So I took one while logging in..

And what you know - my password right there in the clear?? That is not a very safe practice... I know its only a forum and such, and I agree you sure don't have to encrypt the whole site - but not the sending of the username and password?? That needs to be corrected!!

Now my password is complex random - but I assure you it was in the clear.

post-14624-0-50929000-1361862547.png

Not sure what that auth part is there I highlighted, but hid it as well.

So am I correct in that everyone that is logging into neowin is sending username and password in clear??

Link to comment
https://www.neowin.net/forum/topic/1138606-neowin-login-not-secure/
Share on other sites

Yep. May be an IPB issue

I don't think so - I looked on their website, and their form shows it being posted via HTTPS

<form action="[url="view-source:https://www.invisionpower.com/clients/index.php?app=core&module=global&section=login&do=process"]https://www.invisionpower.com/clients/index.php?app=core&module=global&section=login&do=process[/url]" method="[url=""]post[/url]" id='[url=""]login[/url]'>

I am hoping someone just forgot the S there -- but that seems unlikely because you can not access neowin.net via https at all. So maybe they don't have a cert to use?

Most systems that "care" if their accounts could get hacked or not use an SSL connection for at least the login page. Honestly, what damage can really be done on this forum if someone hacks your account? HOPEFULLY people here are smart enough not to use the password on this site on any of their other more important web logins.

I hear yah - it is just a forum.. But personal info about the account could be gleaned form the users control panel. And yeah again great info the password you use here should not be the same as your other logins, etc. But it is still very bad practice, I can not believe it was done on purpose - it must be some oversite somewhere??

I completely agree, hell, every login page that I've coded the password gets hashed and salted before ever even being submitted to the server, and that ALL gets sent across a SSL encrypted connection. Maybe the server admin doesn't want to pay for a cert? lol

I would imagine the option to use https on the login page is an option in the admin area of IPB. I can't can't find a manual though for IPB.

I can see what your saying but I use lots of sites and I would imagine well over half are not secure. Still, if IPB has a flick switch to enable it maybe it should be enabled. Certs are cheap enough these days. Free is cheap right? :)

I use a different random password for every site I use, still there is information about me (email) that a normal user can't see without my password.

Will be interesting to see what the dev's say.

Did some research, by default IPB wants to use an SSL connection, and all of the passwords are hashed in MD5 in the database, but are sent in plain text in the hopes that the sysadmin used an SSL connection for the login page.

Hrm, I think I have about 20ish passwords for my own uses, then a unique password for each of my 200+ clients servers ... Somedays I feel like bashing my head against a wall trying to remember one... but hey, its definitely more secure than some of the other options in the world.

I suppose I'm more surprised it's taken 13 years to discover this (massive?) flaw, but I've alerted Redmak and DaveLegg to have a look.

Thanks BudMan.

I LOL'd at 13 years. What does that say about this "technically savvy" community? Haha :shifty:

  • Like 2

Touche. However, doesn't make it any less humorous. ;)

It's humorous that you don't understand that this isn't actually a huge problem, and can only be resolved by purchasing an expensive SSL certificate for 3 servers, or have a free one cry about it being self signed (creating an unnecessary browser alert for my site).

This topic is now closed to further replies.
  • Posts

    • Yes, it was amusing at the time because even then dbrand was well known for stealing the designs of products from other companies. That’s what they do.
    • Didn’t Dbrand once complain that Casetify was ripping off their designs a well? seems pretty bad of them to try and get around Valve’s copyright this way with that in mind.
    • Dbrand thought they could get away with this Steam Machine case, Valve disagreed by David Uzondu Image via Dbrand Dbrand has cancelled its highly anticipated Companion Cube enclosure for the Valve Steam Machine, which it teased back in November of last year with a concept render and sign-up page, because it did not ask Valve for permission first before manufacturing the case. According to Dbrand, it took the "backwards approach" of building the product first before asking for permission from the copyright holder. Seven months of work went into the project, requiring over a thousand engineering hours from the design team. Workers developed forty-four sets of injection molding tools, making a unique mold for each sub-component of the crate. When the Companion Cube went live on Monday last week, it, according to Dbrand, quickly became the second-fastest-selling product in the company's fifteen-year history, racking up orders for hundreds of thousands of units. Customers eagerly bought the $129.95 deluxe edition or the bare-bones $99.95 version, which the manufacturer cheekily branded as the "Poverty Cube". It was around this time that the legal eagles at Valve descended on the accessory maker with a formal demand. The developer pointed out that the iconic block design remains protected intellectual property from the game Portal, so unlicensed sales had to stop. Dbrand said that all its pleas to salvage the project with the Valve team, including proposals to run a properly licensed release under official terms "with their blessing", fell on deaf ears, so it had no choice but to obey and remove every trace of the product from the internet. If you bought the enclosure, the company said that banks will process your refund by the end of this week, but if it still hasn't arrived in your account by then, you should not hesitate to contact support. The Steam Machine itself is a high-performance console that Valve designed directly to bring PC gaming into the living room. It was announced on 12th November 2025 (the same day Dbrand announced the Cube) and runs on the Linux-based SteamOS, the same OS that powers the Steam Deck. As for the price, due to the shortage of memory and storage chips, the hardware cost landed much higher than people were expecting, starting at $1,049 for the 512 model (without a controller) or $1,128 with the new gamepad. The premium 2 TB model pushes those prices even higher, selling at $1,349 for the standalone console and hitting $1,428 if you want the bundle.
  • Recent Achievements

    • Rookie
      Almohandis went up a rank
      Rookie
    • Apprentice
      jahara21 went up a rank
      Apprentice
    • Reacting Well
      NovaEdgeX earned a badge
      Reacting Well
    • Week One Done
      NovaEdgeX earned a badge
      Week One Done
    • One Year In
      BA the Curmudgeon earned a badge
      One Year In
  • Popular Contributors

    1. 1
      +primortal
      534
    2. 2
      +Edouard
      266
    3. 3
      PsYcHoKiLLa
      148
    4. 4
      Steven P.
      97
    5. 5
      macoman
      57
  • Tell a friend

    Love Neowin? Tell a friend!