Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Insecure Customer Support Login Pages
- ==> Your password may be sent plain-text if you login to these sites
- ==> Plain-text passwords can be sniffed by a packet collector
- ==> Common locations of compromise are wireless at Hotels, Coffee Shops, Airports, etc.
- ==> The intent of this post is to educate end-users on the security of their passwords
- ==> These site were simple to find, they were all on the first 4 pages of a google search for 'support login'
- Reported by neonprimetime security
- http://neonprimetime.blogspot.com
- ******
- NVidia Customer Support
- ==> http://nvidia.custhelp.com/app/utils/login_form/redirect/ask
- ==> Posts to http://nvidia.custhelp.com/ci/ajaxRequest/doLogin/session/
- ==> Form item: "password" = "mypassword"
- Vision Solutions Customer Support
- ==> http://portal.visionsolutions.com/extlogin.aspx
- ==> Posts to http://portal.visionsolutions.com/extlogin.aspx
- ==> Form item: "ctl00$PageContent$LoginBox2$tbpassword" = "mypassword"
- Psychology Software Tools Customer Support
- ==> http://www.pstnet.com/support/login.asp
- ==> Posts to http://www.pstnet.com/support/login.asp?jump=default.htm&email=mylogin%40abc.com&password=mypassword&.save=Login
- ==> Query String: "password" = "mypassword"
- Granbury Restaurant Solutions Customer Support
- ==> http://support.granburyrs.com/support/login.php
- ==> Posts to http://support.granburyrs.com/support/login.php
- ==> Form item: "password" = "mypassword"
- Content DM Customer Support
- ==> http://www.contentdm.org/login/login_USC.asp
- ==> Posts to http://www.contentdm.org/login/login_USC.asp?action=login
- ==> Form item: "user_pwd" = "mypassword"
- InRule Technology Customer Support
- ==> http://support.inrule.com/login.aspx?ReturnUrl=%2fdefault.aspx
- ==> Posts to http://support.inrule.com/login.aspx?ReturnUrl=%2fdefault.aspx
- ==> Form item: "ctl00$ContentPlaceHolder11$Login1$Password" = "mypassword"
- LRS Customer Support
- ==> http://www.lrs.com/eom/ics/login.aspx
- ==> Posts to http://www.lrs.com/eom/ics/login.aspx
- ==> Form item: "ctl00$MainContent$tbPasswordString" = "mypassword"
- Hypercube Customer Support
- ==> http://www.hyper.com/Support/SupportLogin/tabid/466/Default.aspx
- ==> Does not clear out the password on postback
- ==> <input name="dnn:ctr1140:Signin:txtPassword" type="password" ... id="dnn_ctr1140_Signin_txtPassword" ... value="mypassword" ... >
- FileMaker Customer Support
- ==> http://help.filemaker.com/app/utils/login_form/redirect/account%252Foverview/session/
- ==> Posts to http://help.filemaker.com/ci/ajaxRequest/doLogin
- ==> Form item: "password" = "mypassword"
- Axis Communications Customer Support
- ==> http://www.axis.com/login2/login.php
- ==> Posts to http://www.axis.com/login2/login.php
- ==> form-data;name="pwd" 6d:79:70:61:73:73:77:6f:72:64 ("mypassword")
- Profit Key Customer Support
- ==> http://www.profitkey.com/support/support-login/
- ==> Posts to http://profitkey.custhelp.com/ci/ajaxRequest/doLogin
- ==> Form item: "password" = "mypassword"
- BlueAnt Customer Support
- ==> http://www.myblueant.com/support/login.php
- ==> Posts to http://www.myblueant.com/support/login.php
- ==> Form item: "loginpassword" = "mypassword"
- Wyatt Technology Customer Support
- ==> http://www.wyatt.com/Log-in.html
- ==> Posts to http://www.wyatt.com/index.php?option=com_user&lang=en
- ==> Form item: "passwd" = "mypassword"
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement