Recommended Posts

So reading a thread and came across this statement

"Even the neowin login page is not encrypted"

Now I thought to myself - that can not be true.. I know the page itself is not fully encrypted, but that is not an issue the sending of the username and password could be using a https post, etc.

So figured I would take a look see.... Oddly enough, the post for the login looks to be in the clear from the page source

    <form action="https://www.neowin.net/forum/index.php?app=core&module=global&section=login&do=process" method="post" id='login'>

Now I said -- hmmm, I know a little bit about html, but maybe I am missing something and I am looking at it wrong or something. So I did what I know better and that is looking at network sniffs... So I took one while logging in..

And what you know - my password right there in the clear?? That is not a very safe practice... I know its only a forum and such, and I agree you sure don't have to encrypt the whole site - but not the sending of the username and password?? That needs to be corrected!!

Now my password is complex random - but I assure you it was in the clear.

post-14624-0-50929000-1361862547.png

Not sure what that auth part is there I highlighted, but hid it as well.

So am I correct in that everyone that is logging into neowin is sending username and password in clear??

Link to comment
https://www.neowin.net/forum/topic/1138606-neowin-login-not-secure/
Share on other sites

Yep. May be an IPB issue

I don't think so - I looked on their website, and their form shows it being posted via HTTPS

<form action="[url="view-source:https://www.invisionpower.com/clients/index.php?app=core&module=global&section=login&do=process"]https://www.invisionpower.com/clients/index.php?app=core&module=global&section=login&do=process[/url]" method="[url=""]post[/url]" id='[url=""]login[/url]'>

I am hoping someone just forgot the S there -- but that seems unlikely because you can not access neowin.net via https at all. So maybe they don't have a cert to use?

Most systems that "care" if their accounts could get hacked or not use an SSL connection for at least the login page. Honestly, what damage can really be done on this forum if someone hacks your account? HOPEFULLY people here are smart enough not to use the password on this site on any of their other more important web logins.

I hear yah - it is just a forum.. But personal info about the account could be gleaned form the users control panel. And yeah again great info the password you use here should not be the same as your other logins, etc. But it is still very bad practice, I can not believe it was done on purpose - it must be some oversite somewhere??

I completely agree, hell, every login page that I've coded the password gets hashed and salted before ever even being submitted to the server, and that ALL gets sent across a SSL encrypted connection. Maybe the server admin doesn't want to pay for a cert? lol

I would imagine the option to use https on the login page is an option in the admin area of IPB. I can't can't find a manual though for IPB.

I can see what your saying but I use lots of sites and I would imagine well over half are not secure. Still, if IPB has a flick switch to enable it maybe it should be enabled. Certs are cheap enough these days. Free is cheap right? :)

I use a different random password for every site I use, still there is information about me (email) that a normal user can't see without my password.

Will be interesting to see what the dev's say.

Did some research, by default IPB wants to use an SSL connection, and all of the passwords are hashed in MD5 in the database, but are sent in plain text in the hopes that the sysadmin used an SSL connection for the login page.

Hrm, I think I have about 20ish passwords for my own uses, then a unique password for each of my 200+ clients servers ... Somedays I feel like bashing my head against a wall trying to remember one... but hey, its definitely more secure than some of the other options in the world.

I suppose I'm more surprised it's taken 13 years to discover this (massive?) flaw, but I've alerted Redmak and DaveLegg to have a look.

Thanks BudMan.

I LOL'd at 13 years. What does that say about this "technically savvy" community? Haha :shifty:

  • Like 2

Touche. However, doesn't make it any less humorous. ;)

It's humorous that you don't understand that this isn't actually a huge problem, and can only be resolved by purchasing an expensive SSL certificate for 3 servers, or have a free one cry about it being self signed (creating an unnecessary browser alert for my site).

This topic is now closed to further replies.
  • Posts

    • Excuse me for having an opinion, fella'... (Why am I not surprised?...) Congrats on your very informative post however...
    • By the sounds of that wall of Fox News propaganda gibberish attacking the Democratic Party you've already had plenty of "juices" flowing this morning. You've ruined what could have been a productive comment thread.
    • (Topic to get the juices flowing this Sunday morning!...) Actually, the situation has almost nothing to do with "lack of skills", especially since assembly-line skills can be taught to anyone, including Americans, certainly. Rather, the inadequacy-to-impossibility of large-scale tech manufacturing in America today, and the reasons why America finds tech manufacturing completely onerous in the 21st century, has to do with politically driven laws amid a plethora of non-scientific, utterly politicized "science-fact" that is patently false, punitive business taxation at every turn, an array of judicial fines of unimaginable scope and complexity, and, last but not least, American unionization strictures that serve to actually slay job creation and hobble all such manufacturing endeavors in America before they can get off the ground. Globalism emerged, they tell us, as the needed answer to American hubris and an unholy American drive to excel. Unless one is buried under mounds of political propaganda, it's easy to see the absurdity of labeling the employees of SpaceX, for instance, as "unskilled labor"... Etc. ad infinitum. At one time in the recent past, American manufacturing prowess was the envy of the world in a wide variety of technical fields! The current federal and state government roadblocks against America becoming competitive globally in tech manufacturing are considerable, it's true, as anyone with a working brain knows. But remarkably, that is only half the story! The other half of the story is, of course, the corporations themselves... Chinese tech manufacturing is simply unassailable in terms of profits, because the Chinese government wants to see its tech manufacturing second-to-none globally so that no companies/nations can compete in terms of ROI, and China has completely succeeded in that goal. Let's tic-off a few things: *Chinese tariff policies are set according to what is considered best for Chinese business, Chinese employees, and the Chinese people. Huge difference with how things are done with tariffs in the US--as the US government (SCOTUS in this case, Congress in others) plainly feels that tariffs are "unfair" for the limited number of citizens who may pay them, whereas nothing is "unfair" when Congress considers the Personal Income Tax rates to be infinitely hike-able, along with infinitely enlarging annual budget deficits. *The Chinese government boldly subsidizes Chinese companies to artificially amplify their profits. *The Chinese government deliberately refuses to avidly demonize Chinese businesses and does not consider Chinese businesses "the enemy", so very unlike American (D)s these days. *Chinese labor laws and businesses are allowed to set their own labor policies according to what Chinese companies consider is best for companies and their employees... Simply put, American workers in tech manufacturing are not allowed to set their own labor policies! It is the height of hypocrisy for Americans to decry working conditions in China while simultaneously ensuring that American products are manufactured in China, not in the US, simply to maximize profits. There is nothing wrong with making a profit, of course, absolutely nothing. But there is plenty wrong with attempts to normalize hypocrisy of this kind! But rank hypocrisy and the (D) party in the US are longtime bedfellows... The current government in Washington is working overtime to see if it can toss out the horribly poor, failed economic policies of the past, while the (D)s still in Washington work very hard to bring back the stupidity whenever possible. With the right policies in place, America can be an infinitely competitive manufacturer.
  • Recent Achievements

    • Conversation Starter
      jessse3334 earned a badge
      Conversation Starter
    • Reacting Well
      JuvenileDelinquent earned a badge
      Reacting Well
    • One Month Later
      Excellence2025 earned a badge
      One Month Later
    • Week One Done
      Excellence2025 earned a badge
      Week One Done
    • Week One Done
      flexorcist earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      508
    2. 2
      +Edouard
      198
    3. 3
      PsYcHoKiLLa
      152
    4. 4
      Steven P.
      73
    5. 5
      FloatingFatMan
      64
  • Tell a friend

    Love Neowin? Tell a friend!