Recommended Posts

So reading a thread and came across this statement

"Even the neowin login page is not encrypted"

Now I thought to myself - that can not be true.. I know the page itself is not fully encrypted, but that is not an issue the sending of the username and password could be using a https post, etc.

So figured I would take a look see.... Oddly enough, the post for the login looks to be in the clear from the page source

    <form action="https://www.neowin.net/forum/index.php?app=core&module=global&section=login&do=process" method="post" id='login'>

Now I said -- hmmm, I know a little bit about html, but maybe I am missing something and I am looking at it wrong or something. So I did what I know better and that is looking at network sniffs... So I took one while logging in..

And what you know - my password right there in the clear?? That is not a very safe practice... I know its only a forum and such, and I agree you sure don't have to encrypt the whole site - but not the sending of the username and password?? That needs to be corrected!!

Now my password is complex random - but I assure you it was in the clear.

post-14624-0-50929000-1361862547.png

Not sure what that auth part is there I highlighted, but hid it as well.

So am I correct in that everyone that is logging into neowin is sending username and password in clear??

Link to comment
https://www.neowin.net/forum/topic/1138606-neowin-login-not-secure/
Share on other sites

Yep. May be an IPB issue

I don't think so - I looked on their website, and their form shows it being posted via HTTPS

<form action="[url="view-source:https://www.invisionpower.com/clients/index.php?app=core&module=global&section=login&do=process"]https://www.invisionpower.com/clients/index.php?app=core&module=global&section=login&do=process[/url]" method="[url=""]post[/url]" id='[url=""]login[/url]'>

I am hoping someone just forgot the S there -- but that seems unlikely because you can not access neowin.net via https at all. So maybe they don't have a cert to use?

Most systems that "care" if their accounts could get hacked or not use an SSL connection for at least the login page. Honestly, what damage can really be done on this forum if someone hacks your account? HOPEFULLY people here are smart enough not to use the password on this site on any of their other more important web logins.

I hear yah - it is just a forum.. But personal info about the account could be gleaned form the users control panel. And yeah again great info the password you use here should not be the same as your other logins, etc. But it is still very bad practice, I can not believe it was done on purpose - it must be some oversite somewhere??

I completely agree, hell, every login page that I've coded the password gets hashed and salted before ever even being submitted to the server, and that ALL gets sent across a SSL encrypted connection. Maybe the server admin doesn't want to pay for a cert? lol

I would imagine the option to use https on the login page is an option in the admin area of IPB. I can't can't find a manual though for IPB.

I can see what your saying but I use lots of sites and I would imagine well over half are not secure. Still, if IPB has a flick switch to enable it maybe it should be enabled. Certs are cheap enough these days. Free is cheap right? :)

I use a different random password for every site I use, still there is information about me (email) that a normal user can't see without my password.

Will be interesting to see what the dev's say.

Did some research, by default IPB wants to use an SSL connection, and all of the passwords are hashed in MD5 in the database, but are sent in plain text in the hopes that the sysadmin used an SSL connection for the login page.

Hrm, I think I have about 20ish passwords for my own uses, then a unique password for each of my 200+ clients servers ... Somedays I feel like bashing my head against a wall trying to remember one... but hey, its definitely more secure than some of the other options in the world.

I suppose I'm more surprised it's taken 13 years to discover this (massive?) flaw, but I've alerted Redmak and DaveLegg to have a look.

Thanks BudMan.

I LOL'd at 13 years. What does that say about this "technically savvy" community? Haha :shifty:

  • Like 2

Touche. However, doesn't make it any less humorous. ;)

It's humorous that you don't understand that this isn't actually a huge problem, and can only be resolved by purchasing an expensive SSL certificate for 3 servers, or have a free one cry about it being self signed (creating an unnecessary browser alert for my site).

This topic is now closed to further replies.
  • Posts

    • Good think I still have SDRAM and FP RAM sitting around.
    • Fitbit Charge 6 fitness tracker with Google apps is now at its lowest price with 47% off by Fiza Ali Amazon is currently offering the Fitbit Charge 6 fitness tracker at its all-time low price with a 47% discount. The device features an AMOLED touchscreen display protected by Corning Gorilla Glass 3 that should offer improved scratch resistance and durability. The Charge 6 is equipped with a range of sensors including an optical heart rate sensor, a 3-axis accelerometer, built-in GPS with GLONASS support, red and infrared sensors for SpO2 monitoring, a skin temperature sensor, an ambient light sensor, a vibration motor, NFC, and multipurpose electrical sensors compatible with the ECG and EDA Scan apps. Heart rate is recorded every second during exercise tracking and every five seconds during normal daily use. The device requires the Google Health app for setup and synchronisation. Furthermore, Bluetooth provides wireless connectivity for syncing and communication with devices running Apple iOS 16.4 or later and Android 11.0 or later. The tracker stores up to 7 days of minute-by-minute activity data and retains daily activity totals for the previous 30 days. In terms of water resistance, the Fitbit Charge 6 has a 5 ATM rating that should make it suitable for swimming and water activities. The tracker operates in temperatures ranging from 14°F to 113°F and at altitudes of up to 28,000 feet. Moreover, the included Infinity band is made from a flexible silicone material and features a loop-and-peg fastening. The small band fits wrists measuring 5.1 to 6.7 inches, while the large band fits wrists measuring 6.7 to 8.3 inches. Both small and large bands are included in the box. When it comes to battery performance, the Fitbit Charge 6 should deliver up to 7 days of battery life under typical usage conditions. Features such as the Always-On Display, built-in GPS, and SpO2 monitoring increase power consumption and may require more frequent charging. The rechargeable lithium-polymer battery should take approximately two hours to charge from empty to full. Fitbit Charge 6 Fitness Tracker with Google Apps: $85.45 (Amazon US) - 47% off Good to know This Amazon deal is U.S. specific, and not available in other regions unless specified. We only use first-party seller links (at the time of article publishing); ensure that you purchase from a first-party seller link only. Check out Today's Deals on Amazon | or our recent tech deals. Become a Prime member (for Students or SNAP) via Neowin Get Prime Access - Prime for half price (for qualifying Medicaid, EBT, SNAP) Subscribe to Prime Video, Audible Plus, Music Unlimited or Kindle Unlimited via Neowin As an Amazon Associate, we earn from qualifying purchases.
    • google, meta, microsoft, true cancers of modern society
    • TeraCopy 4.0 Build 28 by Razvan Serea TeraCopy is a compact program designed to copy and move files at the maximum possible speed, also providing you with a lot of features. Copy files faster. TeraCopy uses dynamically adjusted buffers to reduce seek times. Asynchronous copy speeds up file transfer between two physical hard drives. Pause and resume transfers. Pause copy process at any time to free up system resources and continue with a single click. Error recovery. In case of copy error, TeraCopy will try several times and in the worse case just skips the file, not terminating the entire transfer. Interactive file list. TeraCopy shows failed file transfers and lets you fix the problem and recopy only problem files. Shell integration. TeraCopy can completely replace Explorer copy and move functions, allowing you work with files as usual. TeraCopy is free for non-commercial use only. For commercial use you need to buy a license. The paid version of the program includes the following features: Copy/move to your favorite folders. Save reports as HTML and CSV files. Select files with the same extension/folder. Remove the selected files from the copy queue. Features added since version 3.17: Enhanced speed graph. New multi-threaded copy engine. Support for copying to multiple targets. Queue system for managing multiple copy operations. Support for receiving files via the LocalSend protocol. TeraCopy entry in the modern Windows Explorer context menu. Integrated toolbar in the title bar. Why receive LocalSend transfers with TeraCopy? Handle file conflicts: Skip, overwrite, or rename files when a file with the same name already exists. LocalSend always creates another copy, which can waste time and disk space, especially when resuming an interrupted transfer. Filter unwanted files: Apply ignore lists or remove files manually before accepting a transfer, so unnecessary files are not downloaded. Better performance on fast networks: In tests over a 10 Gbps connection, TeraCopy received files several times faster than the standard LocalSend app on Windows. TeraCopy 4.0 Build 28 changelog: Fixed a bug where Overwrite behaved as Overwrite All during same-drive move operations. AdvancedInstaller fixed the installer’s security vulnerability: EXE Bootstrapper resolved the %appdata% location incorrectly for the System account. Download: TeraCopy 4.0 Build 28 | 14.6 MB (Freeware, paid upgrade available) View: TeraCopy Website | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • First exciting thing to come to Windows in a long time ! This is the kind of things they should focus on, instead of cramming as much AI as they can in everything.
  • Recent Achievements

    • Reacting Well
      NovaEdgeX earned a badge
      Reacting Well
    • Week One Done
      NovaEdgeX earned a badge
      Week One Done
    • One Year In
      BA the Curmudgeon earned a badge
      One Year In
    • Conversation Starter
      rosiecharles earned a badge
      Conversation Starter
    • First Post
      KMilenkoski1202 earned a badge
      First Post
  • Popular Contributors

    1. 1
      +primortal
      536
    2. 2
      +Edouard
      269
    3. 3
      PsYcHoKiLLa
      150
    4. 4
      Steven P.
      97
    5. 5
      macoman
      61
  • Tell a friend

    Love Neowin? Tell a friend!