Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

December 20th, 2012, 10:56 GMT · By

BLOG

Secondary Twitter “Sign In” Form Found to Transmit Passwords in Plain Text

SHARE:

Adjust text size:


Twitter transmitted passwords in plain text Enlarge picture - Twitter transmitted passwords in plain text
Zohar Alon, the CEO of security solutions provider Dome9, discovered that the “secondary” Twitter sign-in page transmitted user passwords via HTTP, instead of the secure HTTPS.

Fortunately, Twitter rushed to address the issue immediately after being notified, but until a few hours ago, many cybercriminals could have exploited the flaw.

According to TNW, the bug didn’t affect the main sign-in page – the one that users are presented with when they access Twitter. Instead, it affected the drop-down sign-in form which customers can access when viewing a profile or a tweet without being logged in to their accounts.

The main login page transmitted the information in a secure manner, but this alternative page used HTTP, which meant that all passwords could be easily intercepted by someone who was sniffing a potential victim’s network traffic.

After being notified by TNW and Alon about the security hole, Twitter’s security team patched up the issue. However, this fairly serious vulnerability could have been there for some time, impacting the social media site’s 200 million customers.

While this secondary sign-in page is not used as often as the main page, it’s still utilized by a large number of internauts.

TELL US WHAT YOU THINK:

1,989 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Drupal 7.18 and 6.28 Released to Address Security Vulnerabilities

Post Inject Vulnerability Uncovered in SonicWall SonicOS 5.8.1.8

Samsung Exynos Kernel Exploit Highlights the Risks of the BYODTrend

WordPress Pingback Vulnerability Can Be Abused for DDOS Attacks

Sentenced Hacker “Cosmo the God” Said to Be Behind WBC Twitter Hack

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM