Afrikaans
Akan
Albanian
Amharic
Arabic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranรฎ)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
hello again disclosure of credentials
this is what i'm going to discuss right
now this is the bug number three
on our list so i'm gonna focus on
login functionality because obviously
when i talk about
disclosure of credentials then login
functionality
is a natural place to start looking
around right
so let's assume that we're gonna log in
and this is the url related to our login
functionality
https column example.com
login.php so when you go to this url you
are asked to provide your
email and password this url
looks good because we've got https at
the very beginning and https is a secure
protocol
that guarantees confidentiality
integrity
and authentication so we definitely
need to have https that protects the
communication channel
because we don't want our credentials to
be disclosed to the men in the middle
right
that's why we have to make sure that
https
is used here but now the question is
like this
what's going to happen when we change
https
to http right so let's do it
let's change https to http
and see what's gonna happen and there
are basically two scenarios
the one scenario is like this you're
gonna
start with http example.com
example.comlogin.php
and you will be redirected to https
colon example.com login.php
this is really good because it shows
that there is https enforcement
implemented in the web application right
so in other words the web application
does not allow you to go over
http to login functionality it would be
very risky because it would
well it would end up with disclosure of
credentials right
so the web application has to enforce
https
and this is very nice you try with http
and you are redirected to https
but when you try with http and you are
redirected to the same resource so you
start with http and you are redirected
to http
then it basically means that you are
still in the very same place
and obviously https
is not enforced and this is very wrong
because well when https is not enforced
then it actually means that your
credentials
will be disclosed over insecure
http which is just plain text when you
provide them and when you click
login right so this is definitely wrong
and you don't want it to happen
so you have to check whether this kind
of
problem happens in your web application
or not
but even if you see that
this kind of problem does not happen in
login functionality
don't give up and remember that hackers
are
smart they will also check if disclosure
of credentials via
sign up functionality is possible yes
when we talk about disclosure of
credentials well you naturally
think about login but test
login and after that test sign up
there are very similar in both you are
providing email and password
and it may happen i have seen it quite
many times
that everything works very good
for login but in case of signup
well it just works differently and in
sign up you've got the disclosure of
credentials
and in a login you don't have it
so and this is what you have to also
keep in mind
that you shouldn't limit your testing to
login functionality
only you should also check sign up
okay now i believe that this is clear
and
what i want to do is well i want to jump
to
the demo and i want to show you how you
can do this kind of checking
of https enforcement in your
own web application so yeah let's jump
to the demo
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.