Necuno
Court Jester
- Joined
- Sep 27, 2005
- Messages
- 58,566
- Reaction score
- 3,437
Is your ISP sending your client zone detail as plain text or is it actually encrypted ?
Which leaves the question what are these ISPs doing:
Pass:
Fail:
:edit
Now one might ask why is this a bad thing?
Well for one if I casually intercepted your unencrypted detail, it would be very easy to log in and lie dormant. There is no need to abuse, just watch and collect info.
What if I made an err in the OP?
Obviously if I have made an err, then I'll correct it
::edit
*** Apparently Axxess and Cybersmart is also insecure according to Webarica:
:::edit
Seems that the username case insensitivity is due to A) being email or in case of WA/Axxess it's unknown speculation. Should your usename be case sensitive too ?
Which leaves the question what are these ISPs doing:
Pass:
Openweb: Pass ? - HTTPS
Afrihost: Pass - HTTPS, Username is case insensitive.
Mweb: Pass - HTTPS, Username is case insensitive.
Telkom: Pass - HTTPS
Afrihost: Pass - HTTPS, Username is case insensitive.
Mweb: Pass - HTTPS, Username is case insensitive.
Telkom: Pass - HTTPS
Fail:
CyberSmart: Fail? - HTTP, I would strongly advise against and ISP who plays reactionary. ***
Axxess: Fail?, though not sure about second GET - HTTP, Username is case insensitive. ***
WebAfrica: Username is case insensitive.
I am not sure why someone would want to top up someone else’s account,” Fialkov joked, but added that even this is covered by their gig-back guarantee, so if a customer disputes the top-up and it really was not done from their location, a refund will be issued.
Despite being unconvinced of the purpose in securing their ADSL usage and top up pages, Fialkov said that they will do it if their users demand it.
Axxess: Fail?, though not sure about second GET - HTTP, Username is case insensitive. ***
WebAfrica: Username is case insensitive.
:edit
Now one might ask why is this a bad thing?
Well for one if I casually intercepted your unencrypted detail, it would be very easy to log in and lie dormant. There is no need to abuse, just watch and collect info.
What if I made an err in the OP?
Obviously if I have made an err, then I'll correct it
::edit
*** Apparently Axxess and Cybersmart is also insecure according to Webarica:
Hi Prophet
The only way to secure that information would be to use SSL. Unfortunately most of our website (except the customer zone) runs on normal http (for performance reasons). This means that we're unable to post to a secure server and read the response due to cross domain scripting limitations.
http://en.wikipedia.org/wiki/Same_origin_policy
If you can show me a reliable cross-browser technique to get around this issue, then we'll implement it.
Web Africa, Axxess and Cybersmart are "insecure" by that standard. The only reasons why the other guys are secure is because they don have a global login.
Web Africa
http://i45.tinypic.com/ff2s1u.png
Axxess
http://i46.tinypic.com/9vkx3k.png
Cybersmart
http://i46.tinypic.com/333d11y.png
:::edit
Seems that the username case insensitivity is due to A) being email or in case of WA/Axxess it's unknown speculation. Should your usename be case sensitive too ?
Last edited: