Thanks for pointing this out. It is VERY concerning.zer0 wrote:I remember that a while ago, a lot was made of XYplorer installation executable not being signed and that was corrected. However, I wonder how many people know that this forum log-in is not done in a secure manner and their username and password are sent in clear text.
The main forum page is not loaded over HTTPS, so this submit action is not encrypted:A network sniff has confirmed that credentials are sent in clear text as per...Code: Select all
<input type="submit" name="login" value="Login" class="button2" />
I know it's just a forum and such and I am not asking for the whole site to be encrypted, but sending the username and password in the clear? Really?
Forum log-in not secure
Re: Forum log-in not secure
-
admin
- Site Admin
- Posts: 64866
- Joined: 22 May 2004 16:48
- Location: Win8.1, Win10, Win11, all @100%
- Contact:
Re: Forum log-in not secure
I'm currently checking the costs of converting the whole domain to https via my provider.
FAQ | XY News RSS | XY X
Re: Forum log-in not secure
One of my scripts helped you out? Please donate via Paypal
-
admin
- Site Admin
- Posts: 64866
- Joined: 22 May 2004 16:48
- Location: Win8.1, Win10, Win11, all @100%
- Contact:
Re: Forum log-in not secure
Done.
The whole site is now SSL secured. You might want to update your bookmarks.

The whole site is now SSL secured. You might want to update your bookmarks.
FAQ | XY News RSS | XY X
Re: Forum log-in not secure
admin wrote:Done.![]()
The whole site is now SSL secured. You might want to update your bookmarks.
![]()
-
PeterH
- Posts: 2826
- Joined: 21 Nov 2005 20:39
- Location: DE W11Pro 24H2, 1920*1200*100% 3840*2160*150%
Re: Forum log-in not secure
For me this is a big (and necessary) improvement!
So: thanks a lot
So: thanks a lot
Re: Forum log-in not secure
Tag Backup - SimpleUpdater - XYplorer Messenger - The Unofficial XYplorer Archive - Everything in XYplorer
Don sees all [cit. from viewtopic.php?p=124094#p124094]
Don sees all [cit. from viewtopic.php?p=124094#p124094]
Re: Forum log-in not secure
It may have taken a couple of years, but I am glad that we got there in the end 
Reporting a bug? Have a wish? Got a question? Use search - View roadmap - FAQs: Forum + XY site
Windows 7/10
Always using the latest stable two-decimal build
Windows 7/10
Always using the latest stable two-decimal build
XYplorer Beta Club
