Sep 29, 2003

    Insecure Login

    Alexey Pismenskiy Newbie

      When I have got a new account I see new message like 'Login to change your info', where Login has a hyperlink whith parameters ...uname=mylogin&pass=mypass.
      This means that login and password send by HTTP GET, and I'll have some problem - everyone who can see access.log file can get my personal data.