Site Suggestions Got an idea? Post it here.

InterN0T Affiliates:
EvilZonepy1337

SirCapsAlot.NET

Closed Thread
 
LinkBack Thread Tools Display Modes
  #1  
Old 16th January 2010, 02:24
s3my0n's Avatar
InterN0T Crew
 
Join Date: Sep 2009
Location: /home/s3my0n/
Posts: 373
Blog Entries: 3
Rep Power: 8
Reputation: 227
s3my0n has made his way up the systems3my0n has made his way up the systems3my0n has made his way up the system
Intern0t HTTPS option

I was thinking, intern0t only has http server, and it's bad for client side security because somebody can mitm members and get their packets to and fro intern0t plaintext, giving away username and password.

As intern0t runs on apache, I think it's easy to implement https as well as http option for security.

What do you think?
__________________
Quote:
Computers are incredibly fast, accurate, and stupid; humans are incredibly slow, inaccurate and brilliant; together they are powerful beyond imagination.
-Albert Einstein
  #2  
Old 16th January 2010, 15:32
 
Join Date: Jun 2009
Location: UK / Germany
Posts: 39
Rep Power: 6
Reputation: 26
sud0xe is on the way to become something
Re: Intern0t HTTPS option

If your only reason being more defence against MITM attacks then its probably pointless as the HTPS protocall is vulnerable to MITM attack also. Tunneling your HTTP traffic over SSH.
  #3  
Old 16th January 2010, 16:09
s3my0n's Avatar
InterN0T Crew
 
Join Date: Sep 2009
Location: /home/s3my0n/
Posts: 373
Blog Entries: 3
Rep Power: 8
Reputation: 227
s3my0n has made his way up the systems3my0n has made his way up the systems3my0n has made his way up the system
Re: Intern0t HTTPS option

Quote:
Originally Posted by sud0xe View Post
If your only reason being more defence against MITM attacks then its probably pointless as the HTPS protocall is vulnerable to MITM attack also. Tunneling your HTTP traffic over SSH.
I'm saying if HTTPS is easy to implement then why not do it?

And btw, Google spent heaps of money to just make https default protocol for their webservers. So I think there is a reason for Intern0t to do it ^^
__________________
Quote:
Computers are incredibly fast, accurate, and stupid; humans are incredibly slow, inaccurate and brilliant; together they are powerful beyond imagination.
-Albert Einstein

Last edited by s3my0n; 16th January 2010 at 16:15.
  #4  
Old 19th January 2010, 20:37
Tsukasa's Avatar
-=Ninja Pirate=-
 
Join Date: Jun 2008
Location: ::1
Posts: 491
Rep Power: 14
Reputation: 319
Tsukasa is a light in the darkTsukasa is a light in the darkTsukasa is a light in the darkTsukasa is a light in the dark
Re: Intern0t HTTPS option

Ssh tunneling xD
__________________
"...a computer is a stupid machine with the ability to do incredibly
smart things, while computer programmers are smart people with the
ability to do incredibly stupid things. They are, in short, a perfect
match".
  #5  
Old 2nd February 2010, 17:14
MaXe's Avatar
Studying shellcode..
 
Join Date: Jun 2008
Location: Sweden - Ljusdal
Posts: 3,405
Blog Entries: 36
Rep Power: 10
Reputation: 198
MaXe has made his way up the systemMaXe has made his way up the system
Re: Intern0t HTTPS option

At this point it would cost us 50$ if we want a real SSL certificate which is "trusted".

If you're willing to pay 50$ then I'll be happy to add it to InterN0T :-) I can't deny
however, that we might apply a SSL certificate in the future (either our own or a
real "trusted" one) but at the current point it is not going to happen.

I do have a SSL certificate that I can use for our VPS, but that can't be applied
due to a limitation in how 1and1 is set up. However we might move host anyway.
__________________

Quote:
Originally Posted by Norph
MaXe, I really doubt that you are able to browse ANY site more than 2 minutes before you start pwning it xD
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
[Article] Google changes Gmail to Default to HTTPS agriloan Security News and Feeds 0 15th January 2010 17:29
CookieMonster Released! (Https hijacking) DeMoN Hacking Tools & Utilities 1 10th September 2008 12:20


All times are GMT +2. The time now is 13:58.
Copyright ©2007 - Forever, InterN0T & Teh Unkwon

Hosted by 1and1