BetaONE will rise again!


Reply
  #1  
Old 4th Aug 04, 09:16 PM
war59312 war59312 is offline
BetaONE Supporter
 
Join Date: Jul 2001
Location: U.S.A
Posts: 2,220
war59312 has disabled reputation
Send a message via ICQ to war59312 Send a message via AIM to war59312 Send a message via MSN to war59312 Send a message via Yahoo to war59312
Hey,

There is a problem with the cookies for activewin.com.

The login cookie is not encrypted. So your user name and pw are stored in plain text. Very bad. It needs to be encrypted. So atm anyone who has logged into activewin.com and has a cookie on their computer is in danger of getting their user name and pw stolen.

Not only that but the cookie does not expire 1/01/10, so for 6 years. So it will always be there unless you delete it. For a very long time. And since so many people use the same user and pw for many different websites an attack could be pretty dangerous.

Also the forums are not in danger since the pw is encrypted. Though I would also encrypt the user name as it is in plain text atm as well.

Just thought I would give you guys aheads up. I just found 15 computes with activewin user name and pw at class today. lol 13 of them work on different web sites such as yahoo and hotmail.com. lol

Luckly I am a nice guy and told them to change their user name and pws.

Just thought you guys might like to know if you vist that site and keep the cookie so you stay loged in. Your at risk of getting your user name and pw stolen. Pretty easly as it is in plain text. lol

Take Care,
Will
__________________
Ad Muncher Usage Statistics for v4.7 Build 27105/1624
Adverts removed by Ad Muncher: 1,601,933
Approximate bandwidth saved: 12,515 MB
Counter started: April 2, 2003

Download: http://war59312.admuncher.com/download.shtml
Reply With Quote
  #2  
Old 4th Aug 04, 09:49 PM
Hunted's Avatar
Hunted Hunted is offline
Super Moderator
 
Join Date: Jul 2001
Location: Cape Town
Posts: 573
Hunted is on a distinguished road
Send a message via MSN to Hunted
Thnx for the headsup Will.
__________________

AMD
Athlon 64 x2 4800+ - Gigabyte GA-K8NXP-SLI
- 2048MB RAM - 160 GB SEAGATE Barracuda SATA HDD - Gigabyte 7900GT 256MB PCI Express GFX - CHENBRO SILVER Gaming Bomb
Reply With Quote
  #3  
Old 9th Aug 04, 08:03 AM
Jarod888's Avatar
Jarod888 Jarod888 is offline
Administrator
 
Join Date: Jan 2002
Posts: 649
Jarod888 is an unknown quantity at this point
Send a message via MSN to Jarod888
Moving this to the Security Forum
__________________

Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
NSA Security Guide for MacOS X NewsBot NeoWin News 0 29th Oct 04 10:30 PM
Windows v Linux security: the real facts NewsBot NeoWin News 0 22nd Oct 04 11:00 PM


All times are GMT +1. The time now is 10:02 PM.


Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.