Random Technical Question

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • herogee
    Addiction started
    • Jun 2004
    • 369

    Random Technical Question

    Was just wondering, when somebody is about to log in to MS and types in the username and password, is the password encrypted when it is sent over the net?
    If you're fond of sand dunes and salty air,
    quaint little villages here and there ...
  • picklemonkey
    Double hoodie beer monster
    • Jun 2004
    • 15373

    #2
    no. The password box is a simple text box that is POSTed to the server in plain text

    Comment

    • Kamal
      Administrator
      • May 2002
      • 28835

      #3
      Pickles not entirely right, we're not using an https folder but the passwords are converted into funky characters by the php when you hit the submit button.... while the information itself is not encrypted, its changed when it travels over the internet and so its not in plain text... once it reaches the db, its stored there in the same format and so even as an admin, I cannot read your password in the database because it is changed

      hope that helps

      -e-
      www.mjwebhosting.com

      Jib says:
      he isnt worth the water that splashes up into your asshole while you're shitting
      Originally posted by ace_dl
      Guys and Gals, I have to hurry/leaving for short-term vacations.
      I won't be back until next Tuesday, so if Get Carter is the correct answer, I would appreciate of someone else posts a new cap for me

      Comment

      • TomTom
        Paging Doctor Weeds...we have a shortage on 1st St.
        • May 2002
        • 16206

        #4
        But we can change it to suckmyballsyoudirtymofo or whatever.

        Comment

        • herogee
          Addiction started
          • Jun 2004
          • 369

          #5
          [...] so even as an admin, I cannot read your password in the database
          Right, thanks for the answer. The point of my question was to find out whether someone using a packet sniffer could pick up the passwords, not whether the admins can read them ...

          Just curious about password security ... I ask myself the same thing everytime I log in to yahoo.
          If you're fond of sand dunes and salty air,
          quaint little villages here and there ...

          Comment

          • picklemonkey
            Double hoodie beer monster
            • Jun 2004
            • 15373

            #6
            Originally posted by Encryption
            Pickles not entirely right, we're not using an https folder but the passwords are converted into funky characters by the php when you hit the submit button.... while the information itself is not encrypted, its changed when it travels over the internet and so its not in plain text... once it reaches the db, its stored there in the same format and so even as an admin, I cannot read your password in the database because it is changed

            hope that helps

            -e-
            You're wrong. I looked at the source code and it submits the plain text user/pass to the login.php, which might encrypt it... but it's still submitted over the network in plain text. I just verified this with a packet sniffer.

            It's sent in plain text.

            Comment

            • Kamal
              Administrator
              • May 2002
              • 28835

              #7
              they can pick it up but it would take a good bit of phpbb decoding to see how the passwords are restructured.....as I said, while the packet itself if not encrypted during its journey over the net, password itself is changed so no one truly knows what your password is

              -e-
              www.mjwebhosting.com

              Jib says:
              he isnt worth the water that splashes up into your asshole while you're shitting
              Originally posted by ace_dl
              Guys and Gals, I have to hurry/leaving for short-term vacations.
              I won't be back until next Tuesday, so if Get Carter is the correct answer, I would appreciate of someone else posts a new cap for me

              Comment

              • skahound
                Someone MARRY ME!! LOL
                • Jun 2004
                • 11411

                #8
                I sniff girls' panties.
                A good shower head and my right hand - the two best lovers that I ever had.

                Comment

                • picklemonkey
                  Double hoodie beer monster
                  • Jun 2004
                  • 15373

                  #9
                  Originally posted by herogee
                  [...] so even as an admin, I cannot read your password in the database
                  Right, thanks for the answer. The point of my question was to find out whether someone using a packet sniffer could pick up the passwords, not whether the admins can read them ...

                  Just curious about password security ... I ask myself the same thing everytime I log in to yahoo.
                  According to -e-, Admins can't read them.

                  Anybody else can if they're using a packet sniffer. I just verified this.

                  Comment

                  • PsynceFiction[MS]
                    Platinum Poster
                    • Jun 2004
                    • 1332

                    #10


                    -Psynce-
                    www.boelsphotography.be

                    Comment

                    • Kamal
                      Administrator
                      • May 2002
                      • 28835

                      #11
                      Originally posted by picklemonkey
                      Anybody else can if they're using a packet sniffer. I just verified this.
                      how'd you verify this again ?
                      www.mjwebhosting.com

                      Jib says:
                      he isnt worth the water that splashes up into your asshole while you're shitting
                      Originally posted by ace_dl
                      Guys and Gals, I have to hurry/leaving for short-term vacations.
                      I won't be back until next Tuesday, so if Get Carter is the correct answer, I would appreciate of someone else posts a new cap for me

                      Comment

                      • Kamal
                        Administrator
                        • May 2002
                        • 28835

                        #12
                        no wait let me guess, you put a packet sniffer on your local machine and had it pick up the passwords ?
                        www.mjwebhosting.com

                        Jib says:
                        he isnt worth the water that splashes up into your asshole while you're shitting
                        Originally posted by ace_dl
                        Guys and Gals, I have to hurry/leaving for short-term vacations.
                        I won't be back until next Tuesday, so if Get Carter is the correct answer, I would appreciate of someone else posts a new cap for me

                        Comment

                        • picklemonkey
                          Double hoodie beer monster
                          • Jun 2004
                          • 15373

                          #13


                          I work in IT. I already have a packet sniffer installed.

                          Comment

                          • Civic_Zen
                            Platinum Poster
                            • Jun 2004
                            • 1116

                            #14
                            You da man picklez
                            "The more corrupt the state, the more numerous the laws." - Tacitus (55-117 A.D.)
                            "That government is best which governs the least, because its people discipline themselves."
                            - Thomas Jefferson

                            Comment

                            • Kamal
                              Administrator
                              • May 2002
                              • 28835

                              #15
                              damn, u PWNED Me on that one....

                              I find it hard to believe that its printing out the passwords directly on an http transfer, I know I read it somewhere on their forums that passwords are changed and transmitted over the net.....

                              guess that answers your Q herogee....

                              -e-
                              www.mjwebhosting.com

                              Jib says:
                              he isnt worth the water that splashes up into your asshole while you're shitting
                              Originally posted by ace_dl
                              Guys and Gals, I have to hurry/leaving for short-term vacations.
                              I won't be back until next Tuesday, so if Get Carter is the correct answer, I would appreciate of someone else posts a new cap for me

                              Comment

                              Working...