Reseller Hosting, Shared Hosting, Dedicated Hosting by Vortech Inc.

Go Back   Reseller Hosting, Shared Hosting, Dedicated Hosting by Vortech Inc. > >> General Public > Chit Chat Public
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Chit Chat Public Talk about any thing you want! This forum is public.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 02-20-2004, 01:04 PM
jaymac jaymac is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Exclamation Security Concerns with MSSQL Manager

Hey Guys,

I was a little concerned today when I logged into the MSSQL manager today for the first time on my website. When I logged on by clicking on the magnifying glass next to MSSQL manager in my control panel, I noticed that my username and password were embedded right into the front of the URL! Thats pretty poor security! On a shared computer this URL is saved in the history, along with my password for any one to see. Also, since the log in didnt seem to work, I modified the url slightly and went to this page:

www.arguecity.com/MSSQL/app/connect.aspx

You will notice that when you go there, the password box is actually just a plain text box!

Im not sure who's responsibility it is to fix this, but wow!

Jason
Reply With Quote
  #2  
Old 02-20-2004, 01:16 PM
admin's Avatar
admin admin is offline
Vortech Inc. Owner
Owner
 
Location: Orlando FL
Send a message via ICQ to admin
Quote:
Originally Posted by jaymac
Hey Guys,

I was a little concerned today when I logged into the MSSQL manager today for the first time on my website. When I logged on by clicking on the magnifying glass next to MSSQL manager in my control panel, I noticed that my username and password were embedded right into the front of the URL! Thats pretty poor security! On a shared computer this URL is saved in the history, along with my password for any one to see. Also, since the log in didnt seem to work, I modified the url slightly and went to this page:

www.arguecity.com/MSSQL/app/connect.aspx

You will notice that when you go there, the password box is actually just a plain text box!

Im not sure who's responsibility it is to fix this, but wow!

Jason


This is really used widely by many CP's and other software. Now does not even work as it use to because of MS making some changes to IE. H-Sphere should be changing WebShell, aspx EM, and someother stuff will change to login anther way but it may stills how the username and password, there is not many ways to pass this info to anther server with out using something in the URL.
__________________
Brad Pugh
http://www.vortechhosting.com
------

Local System/Network Monitor
http://nagios.hsphere.cc/
Login:guest Pass:guest
XML FEED http://nagios.hsphere.cc/feed.xml
------

My Other Life:
Reply With Quote
  #3  
Old 02-20-2004, 01:20 PM
jaymac jaymac is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
How about not passing it at all? Have the magnifying glass go to a regular, secure, login page?
Reply With Quote
  #4  
Old 02-20-2004, 07:09 PM
Brangwyn Brangwyn is offline
T3CHN0 STUD
Vortech Inc. Customer
 
Location: New Zealand (Wellington)
Might want to post suggestions at psofts forum www.psoft.net we're pretty much stuck with whatever they decide to churn out
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 05:53 AM.


Powered by vBulletin Version 3.5.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Vortech Inc. ©2005
Page generated in 0.56266 seconds with 19 queries
[Output: 48.58 Kb. compressed to 45.46 Kb. by saving 3.13 Kb. (6.43%)]