Thread: Site security.
View Single Post
      08-29-2017, 09:14 PM   #3
F32Fleet
Lieutenant General
F32Fleet's Avatar
United_States
3575
Rep
10,355
Posts

Drives: 2015 435i
Join Date: May 2005
Location: Southeastern US

iTrader: (0)

Quote:
Originally Posted by The Wind Breezes
You're right. I just performed a packet capture of the site and login credentials are sent in plaintext although the username is hashed to md5. Not so good, and worse, it's hash WITHOUT A SALT! So it would be really easy to decode most user's passwords if you could grab their traffic. Or someone could insert their own page.
I don't think the admins are interested in commenting about this.
__________________
"Drive more, worry less. "

435i, MPPK, MPE, M-Sport Line
Appreciate 0