HTTP can be sniffed

Status
Not open for further replies.

Youkai

Demon
OP
Member
Joined
Jul 1, 2004
Messages
2,552
Trophies
1
Age
36
Location
Germany , NRW
XP
2,445
Country
Germany
As I am learning to become an IT guy I started to learn packet sniffer which seem to be VERY easy nowadays ....

Now just for fun I logged into GBATemp while having the packet sniffer running and say what, the Password and Username is send in PLAIN TEXT !
So if you are every connected to an Open W-Lan Hotspot NEVER login to GBATemp !!! it takes about 2 seconds to get your username and Password.


Maybe someone from the Administration Team could fix this and add an encryption ?
 

TecXero

Technovert
Member
Joined
Apr 13, 2014
Messages
2,810
Trophies
0
Location
Mainframe
XP
1,040
Country
United States
I never really thought about the security on here. I use an unique passcode for this site and I don't consider my account or any of its information important. I guess a person could get my email address, but nothing else. I mean, yeah security is important, but this site isn't exactly high priority for me, and I'd assume most other users.
 

Duo8

Well-Known Member
Member
Joined
Jul 16, 2013
Messages
3,613
Trophies
2
XP
3,032
Country
Vietnam
I never knew there is a https version oO?
why the hell are there two XD

//seems to be secure ;) at least not as easy as reading some plain text which could do any child.
Costello was asked about HTTPS once and he said that the login info is not important enough.
Still he added HTTPS some months ago and finished it (all page content) with V5. Though I don't know if HTTPS is the default or not.
 

Brewzip

Well-Known Member
Newcomer
Joined
Feb 6, 2015
Messages
54
Trophies
0
Age
29
XP
96
Country
Italy
The default one for the site is HTTP.
Probably Costello keeps both because there are some other works to do to V5.

However, I don't think this is that kind of situation. Maybe the current solution is simply not optimized, because it's not considered a priority. For me, it's a bad practice.
In this state, the site has the advantage of compatibility with old browser that doesn't support HTTPS. But having two version is less secure.

I noticed another "bad procedure", not related to security, but SEO.
After so many years, the site can still be visited using two identical versions (www and non www).
One of gbatemp.net and www.gbatemp.net should send a redirect 301 to the other.
 

The Real Jdbye

*is birb*
Member
Joined
Mar 17, 2010
Messages
23,333
Trophies
4
Location
Space
XP
13,909
Country
Norway
The default one for the site is HTTP.
Probably Costello keeps both because there are some other works to do to V5.

However, I don't think this is that kind of situation. Maybe the current solution is simply not optimized, because it's not considered a priority. For me, it's a bad practice.
In this state, the site has the advantage of compatibility with old browser that doesn't support HTTPS. But having two version is less secure.

I noticed another "bad procedure", not related to security, but SEO.
After so many years, the site can still be visited using two identical versions (www and non www).
One of gbatemp.net and www.gbatemp.net should send a redirect 301 to the other.
It's only less secure if you use the HTTP version.
Anyway, it doesn't really matter, it's not the kind of account that's interesting to skiddies :P
 

Costello

Headmaster
Administrator
Joined
Oct 24, 2002
Messages
14,203
Trophies
4
XP
19,746
that's not even a subject.
HTTP *is* sniffable, no matter how hard you try, if you don't use HTTPS you are exposing yourself.
If you are worried that people on your wifi network might be sniffing your packets, just use the HTTPS version.
 
  • Like
Reactions: Minox
Status
Not open for further replies.

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
  • SylverReZ @ SylverReZ:
    @Sonic Angel Knight, Is that SAK I see. :ninja:
  • BigOnYa @ BigOnYa:
    What a weird game
  • K3Nv2 @ K3Nv2:
    Yeah I wanted to see shards of the titanic
  • BigOnYa @ BigOnYa:
    I kept thinking jaws was gonna come up and attack
  • K3Nv2 @ K3Nv2:
    Jaws is on a diet
  • K3Nv2 @ K3Nv2:
    Damn power went out
  • BigOnYa @ BigOnYa:
    Ok xdqwerty, your little bro prob tripped On the cord and unplugged you
  • K3Nv2 @ K3Nv2:
    Ya I'm afraid of the dark hug me
  • BigOnYa @ BigOnYa:
    Grab and hold close your AncientBoi doll.
  • K3Nv2 @ K3Nv2:
    Damn didn't charge my external battery either
  • BigOnYa @ BigOnYa:
    Take the batteries out of your SuperStabber3000... Or is it gas powered?
  • K3Nv2 @ K3Nv2:
    I stole batteries from your black mamba
    +1
  • K3Nv2 @ K3Nv2:
    My frozen food better hold up for an hour I know that
  • BigOnYa @ BigOnYa:
    Or else gonna be a big lunch and dinner tomorrow.
  • BigOnYa @ BigOnYa:
    Did you pay your power bill? Or give all yo money to my wife, again.
  • K3Nv2 @ K3Nv2:
    Oh good the estimated time is the same exact time they just said
    +1
  • BigOnYa @ BigOnYa:
    Load up your pc and monitor, and head to a McDonalds dining room, they have free WiFi
  • K3Nv2 @ K3Nv2:
    Sir please watch your porn in the bathroom
    +1
  • BigOnYa @ BigOnYa:
    No sir we can not sell you anymore apple pies, after what you did with the last one.
  • K3Nv2 @ K3Nv2:
    We ran out
  • HiradeGirl @ HiradeGirl:
    for your life
    +1
  • K3Nv2 @ K3Nv2:
    My life has no value my fat ass is staying right here
    K3Nv2 @ K3Nv2: My life has no value my fat ass is staying right here