|
|
| |
Register.com is used by many site administrators for maintaining their site domains. It allows registering a new domain and provides other services related to site administration.
Apparently, register.com pass the administrative password in clear text, making it possible for outsiders to eavesdrop and discover the password, and then make malicious changes in the site's information (such as redirecting the site's traffic to another site). |
| |
Credit:
This information has been provided by: r3wt at maple.kgmweb.net
|
| |
Register.com submits the password used to protect domain records in a completely unencrypted way, making it possible for anyone that is able to sniff your network a complete access to your domain record.
Example:
Content-type: application/x-www-form-urlencoded
Content-length: 73
usa_id=&name=bill&password=here_is_my_password&domain=example.com&sid=4833021233&x=9&y=11
|
|
|
|
|
|
|
|