Facebook   Twitter    e-mail newsletter    YouTube    RSS Feed    Android App    iPhone and iPad App     BlackBerry App    


Page 1 of 4 1 234 LastLast
Results 1 to 15 of 57

Thread: ISP: Your login detail is insecure. (Clientzone)

  1. #1

    Exclamation ISP: Your login detail is insecure. (Clientzone)

    Is your ISP sending your client zone detail as plain text or is it actually encrypted ?

    Which leaves the question what are these ISPs doing:

    Pass:
    Openweb: Pass ? - HTTPS
    Afrihost: Pass - HTTPS, Username is case insensitive.
    Mweb: Pass - HTTPS, Username is case insensitive.
    Telkom: Pass - HTTPS

    Fail:
    CyberSmart: Fail? - HTTP, I would strongly advise against and ISP who plays reactionary. ***
    I am not sure why someone would want to top up someone else’s account,” Fialkov joked, but added that even this is covered by their gig-back guarantee, so if a customer disputes the top-up and it really was not done from their location, a refund will be issued.

    Despite being unconvinced of the purpose in securing their ADSL usage and top up pages, Fialkov said that they will do it if their users demand it.
    Axxess: Fail?, though not sure about second GET - HTTP, Username is case insensitive. ***

    WebAfrica: Username is case insensitive.
    Initial - Fail - HTTP. Clear text over http.
    Current - Pass ? - HTTPS. Login is now https, but what about that create session. Then there is also the cookie issue:
    Cookies - Fail? Clear text as here or here.


    :edit
    Now one might ask why is this a bad thing?
    Well for one if I casually intercepted your unencrypted detail, it would be very easy to log in and lie dormant. There is no need to abuse, just watch and collect info.

    What if I made an err in the OP?
    Obviously if I have made an err, then I'll correct it


    ::edit
    *** Apparently Axxess and Cybersmart is also insecure according to Webarica:

    Quote Originally Posted by wakevinr View Post
    Hi Prophet

    The only way to secure that information would be to use SSL. Unfortunately most of our website (except the customer zone) runs on normal http (for performance reasons). This means that we're unable to post to a secure server and read the response due to cross domain scripting limitations.
    http://en.wikipedia.org/wiki/Same_origin_policy

    If you can show me a reliable cross-browser technique to get around this issue, then we'll implement it.

    Web Africa, Axxess and Cybersmart are "insecure" by that standard. The only reasons why the other guys are secure is because they don have a global login.

    Web Africa
    http://i45.tinypic.com/ff2s1u.png

    Axxess
    http://i46.tinypic.com/9vkx3k.png

    Cybersmart
    http://i46.tinypic.com/333d11y.png

    :::edit
    Seems that the username case insensitivity is due to A) being email or in case of WA/Axxess it's unknown speculation. Should your usename be case sensitive too ?
    Last edited by Pr⊕phet; 16-08-2012 at 07:44 PM.
    "The oldest and strongest emotion of mankind is fear, and the oldest and strongest kind of fear is fear of the unknown" - H.P. Lovecraft

  2. #2

    Default

    Not such a big issue for me since the ISP can tell me which telephone numbers used my account. Similarly if someone steals my router and just plugs it in and uses it I got their home address through home number.

  3. #3

    Default

    Quote Originally Posted by twicode View Post
    Not such a big issue for me since the ISP can tell me which telephone numbers used my account. Similarly if someone steals my router and just plugs it in and uses it I got their home address through home number.
    It's about safe practices. It is the clientzone we are speaking about, added the detail... my bad.


    Biggest stupidity is to treat symptoms.
    Last edited by Pr⊕phet; 02-08-2012 at 09:22 AM.
    "The oldest and strongest emotion of mankind is fear, and the oldest and strongest kind of fear is fear of the unknown" - H.P. Lovecraft

  4. #4
    Super Grandmaster
    Join Date
    Aug 2008
    Location
    cape town
    Posts
    5,153

    Default

    mweb is encrypted
    Pc:Amd 750k,MSI A85XA-G65,8gb ram,GTX 480 850/2000 ,Vertex 2 100gb
    Laptop : HP Envy 14 I5 460m,4GB ram,HD5650M,256GB SSD,1600x900 Radiance display!

  5. #5
    Super Grandmaster
    Join Date
    Feb 2005
    Location
    Previously this post ->
    Posts
    24,031

    Default

    Nice post! Consider the other information available (bank details etc) on these PIM systems. Not to mention the lazy will use one password for most sites so if they can access this place they will most likely try other accounts (GMail etc)
    Quote Originally Posted by reactor_sa
    ^ fountain of knowledge

  6. #6
    SmoothSupport The_Librarian's Avatar
    Join Date
    Apr 2005
    Location
    Lothlorien
    Posts
    73,350
    Blog Entries
    19

    Default

    Never had a problem with my Afrihost account details getting stolen

    You still need to test Telkom
    Last edited by The_Librarian; 02-08-2012 at 11:19 AM.
    Christ-mass is NOT for Christians. Jeremiah 10.
    Is the 10 Commandments for Christians?

    Saturday is the Seventh day, Sunday is the first day.

    Shmiert Shpammer

  7. #7

    Default

    Quote Originally Posted by hereticangel View Post
    mweb is encrypted
    Totally forgot about them
    "The oldest and strongest emotion of mankind is fear, and the oldest and strongest kind of fear is fear of the unknown" - H.P. Lovecraft

  8. #8

    Default

    Quote Originally Posted by The_Librarian View Post
    Never had a problem with my Afrihost account details getting stolen

    You still need to test Telkom
    Seems telkom has it down.
    "The oldest and strongest emotion of mankind is fear, and the oldest and strongest kind of fear is fear of the unknown" - H.P. Lovecraft

  9. #9
    Super Grandmaster gregmcc's Avatar
    Join Date
    Jun 2006
    Location
    127.0.0.1, United Kingdom
    Posts
    16,356

    Default

    Quote Originally Posted by twicode View Post
    Not such a big issue for me since the ISP can tell me which telephone numbers used my account. Similarly if someone steals my router and just plugs it in and uses it I got their home address through home number.
    That's not the point. What other info can someone get using your account - phone number/ id number / email / address. You dont need much more than that for identify theft.

  10. #10
    Web Africa Representative WAJeff's Avatar
    Join Date
    May 2009
    Location
    Cape Town
    Posts
    1,506

    Default

    Quote Originally Posted by WAJeff View Post
    Will have a chat with the Dev Manager when he comes in.
    Waiting for feedback on this one.

  11. #11

    Default

    Quote Originally Posted by twicode View Post
    Not such a big issue for me since the ISP can tell me which telephone numbers used my account. Similarly if someone steals my router and just plugs it in and uses it I got their home address through home number.
    Resets your email password, logs into your mailbox, steals any useful info there (bank account details, ID number). Sends request to your bank to change your Cellphone number linked to your bank account using details found in your mailbox. Resets online banking password. Adds beneficiaries. Increases limits. Game over.

  12. #12
    Grandmaster Dan C's Avatar
    Join Date
    Nov 2005
    Location
    East London
    Posts
    1,524

    Default

    Yeah WebAfrica is wide open, noticed that a while back but didn't really bother.
    Never test the depth of the water with both feet ... | TrackMania SA

  13. #13

    Default

    Quote Originally Posted by WAJeff View Post
    Waiting for feedback on this one.
    mmkay
    "The oldest and strongest emotion of mankind is fear, and the oldest and strongest kind of fear is fear of the unknown" - H.P. Lovecraft

  14. #14
    Web Africa Representative WAJeff's Avatar
    Join Date
    May 2009
    Location
    Cape Town
    Posts
    1,506

    Default

    We've pushed a change live earlier, can you guys please double check?

  15. #15

    Default

    Quote Originally Posted by WAJeff View Post
    We've pushed a change live earlier, can you guys please double check?
    Doesn't look if it is secure:

    "The oldest and strongest emotion of mankind is fear, and the oldest and strongest kind of fear is fear of the unknown" - H.P. Lovecraft

Page 1 of 4 1 234 LastLast

Similar Threads

  1. Afrihost Clientzone is down!
    By elriconess in forum ADSL ISP Discussions
    Replies: 5
    Last Post: 24-08-2011, 01:39 PM
  2. Afrihost Clientzone
    By kimbo in forum ADSL ISP Discussions
    Replies: 10
    Last Post: 10-11-2009, 09:58 AM
  3. Are atheists insecure?
    By angelik in forum Philosophical Debates
    Replies: 141
    Last Post: 03-03-2009, 12:05 AM
  4. Switching from Router login to WinXP login
    By Maximus in forum ADSL Discussions
    Replies: 5
    Last Post: 26-01-2006, 11:04 PM

Bookmarks

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •