Site Suggestions Got an idea? Post it here.

InterN0T Affiliates:
EvilZonepy1337

SirCapsAlot.NET

Reply
 
LinkBack Thread Tools Display Modes
  #1  
Old 16th January 2010, 03:24
s3my0n's Avatar
InterN0T Crew
 
Join Date: Sep 2009
Location: 74.208.63.76
Posts: 245
Blog Entries: 1
Rep Power: 3
Reputation: 127
s3my0n will become a Token soons3my0n will become a Token soon
Intern0t HTTPS option

I was thinking, intern0t only has http server, and it's bad for client side security because somebody can mitm members and get their packets to and fro intern0t plaintext, giving away username and password.

As intern0t runs on apache, I think it's easy to implement https as well as http option for security.

What do you think?
__________________
s3my0n@intern0t.net:~$ whoami

RuSH4ck3R
Reply With Quote
  #2  
Old 16th January 2010, 16:32
 
Join Date: Jun 2009
Location: UK / Germany
Posts: 39
Rep Power: 4
Reputation: 26
sud0xe is on the way to become something
Re: Intern0t HTTPS option

If your only reason being more defence against MITM attacks then its probably pointless as the HTPS protocall is vulnerable to MITM attack also. Tunneling your HTTP traffic over SSH.
Reply With Quote
  #3  
Old 16th January 2010, 17:09
s3my0n's Avatar
InterN0T Crew
 
Join Date: Sep 2009
Location: 74.208.63.76
Posts: 245
Blog Entries: 1
Rep Power: 3
Reputation: 127
s3my0n will become a Token soons3my0n will become a Token soon
Re: Intern0t HTTPS option

Quote:
Originally Posted by sud0xe View Post
If your only reason being more defence against MITM attacks then its probably pointless as the HTPS protocall is vulnerable to MITM attack also. Tunneling your HTTP traffic over SSH.
I'm saying if HTTPS is easy to implement then why not do it?

And btw, Google spent heaps of money to just make https default protocol for their webservers. So I think there is a reason for Intern0t to do it ^^
__________________
s3my0n@intern0t.net:~$ whoami

RuSH4ck3R

Last edited by s3my0n; 16th January 2010 at 17:15.
Reply With Quote
  #4  
Old 19th January 2010, 21:37
Tsukasa's Avatar
-=Ninja Pirate=-
 
Join Date: Jun 2008
Location: ::1
Posts: 457
Rep Power: 11
Reputation: 287
Tsukasa is a light in the darkTsukasa is a light in the darkTsukasa is a light in the dark
Re: Intern0t HTTPS option

Ssh tunneling xD
__________________
"...a computer is a stupid machine with the ability to do incredibly
smart things, while computer programmers are smart people with the
ability to do incredibly stupid things. They are, in short, a perfect
match".
Reply With Quote
  #5  
Old 2nd February 2010, 18:14
MaXe's Avatar
The BOFH
 
Join Date: Jun 2008
Location: Sweden - Ljusdal
Posts: 2,718
Blog Entries: 31
Rep Power: 10
Reputation: 146
MaXe will become a Token soonMaXe will become a Token soon
Re: Intern0t HTTPS option

At this point it would cost us 50$ if we want a real SSL certificate which is "trusted".

If you're willing to pay 50$ then I'll be happy to add it to InterN0T :-) I can't deny
however, that we might apply a SSL certificate in the future (either our own or a
real "trusted" one) but at the current point it is not going to happen.

I do have a SSL certificate that I can use for our VPS, but that can't be applied
due to a limitation in how 1and1 is set up. However we might move host anyway.
__________________
Code:
                                ____/____\_________________
                      \|/      | OMG IT'S TEH LEET STORY!! |
    /*\         /\    -*-      |______  ________/\_________|
   // \\       /  \   /|\        /    \/    \  /  \
  /// \\\     /    \            /            \/    \
   // \\     /      \          /      \o/     \     \
    | |     /        \        /        |       \     \
 ___| |____/          \______/________/ \_______\_____\_________
          /     o      \
               #"=-
               /\
 __________________________________________________________
    On a mission, to find the lost member of Teh Unkwon.. 
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
[Article] Google changes Gmail to Default to HTTPS agriloan Security News and Feeds 0 15th January 2010 18:29
CookieMonster Released! (Https hijacking) DeMoN Hacking Tools & Utilities 1 10th September 2008 13:20


All times are GMT +2. The time now is 23:36.
Copyright ©2007 - Forever, InterN0T & Teh Unkwon

Hosted by 1and1