• Hello guest! Are you a Bearded Dragon enthusiast? If so we invite you to join our community and see what it has to offer. Our site is specifically designed for you and it's a great place for Beardie enthusiasts to meet online. Once you join you'll be able to post messages, upload pictures of your dragons and enclosures and have a great time with other Bearded Dragon enthusiasts. Sign up today!

Site security or lack thereof

Status
Not open for further replies.

HereFishyFishy

Bearded Dragon Egg
Messages
15
Hi guys,

As a computer programmer I would be remiss if I did not alert you to a few points about this site.
Having looked through it's HTML, it's Divs and php/ html "post" and "get" requests (I'm sorry if this is too technical), I have to say this site is not secure at all, it would be extremely trivial for me to harvest ALL of the users passwords and physical locations - I'm not trying to worry you but it is true.

Take the term "POST" I used - this means what ever information you type in the password box is sent to the server hidden, but not secure - just hidden from plain view ( and I'm not talking about the **** that obscures your password, that is just client(web browser) looking at the HTML fields settings). so this can be intercepted by of the 1 to 5 million servers or computers it runs through to get to tapatalk's (sites hosts) server. there should be client and server SSL (secure sockets layer) it is crazy that a website is not running HTTPS!

for fear of going off in a technical rant I will just say this : any information sent by http and not https is INSECURE.
I am a hobbyist programmer, if an actual bad guy saw this your personal information is up for grabs.

example:

I pull up a users username, type it in the login, i use a quick bit of knowhow in the password box ( I'll not share this here as it's not really good to feed people hacking tips) and log into your account.

I then pull up your session ID in my browser, I now have your cookie, I can now inject it into my own HTTP requests to the server, I can now change your password - after viewing it of course.

I take your registration email and password to other sites ( or if I'm smart I make a program to ping sites) using your email and password, I get onto amazon and buy myself some lovely headphones to an address on your credit cards, and the whole plethora of other scenarios you can imagine.

Site security is a big deal, someone either needs to lay for a SSL license and start encrypting the site or I'd suggest a move.

At the very least don't let your password here be anywhere else, same with your email address.

Thanks
 

HereFishyFishy

Bearded Dragon Egg
Messages
15
Site is not hosted by tapatalk - I got confused, the tapatalk is actually a section of code of phones accessing the site, it seems to be going through

  • Hosting provider: Digital Ocean
  • IP Address: 107.170.109.75
  • Name Servers:
  • ns2.dnsmadeeasy.com
  • ns3.dnsmadeeasy.com
  • ns4.dnsmadeeasy.com
  • ns1.dnsmadeeasy.com
  • ns0.dnsmadeeasy.com
 

HereFishyFishy

Bearded Dragon Egg
Messages
15
Domain Name: BEARDEDDRAGONFORUM.COM
Registry Domain ID: 1420924560_DOMAIN_COM-VRSN
Registrar WHOIS Server: whois.godaddy.com
Registrar URL: http://www.godaddy.com
Update Date: 2015-03-13T18:13:47Z
Creation Date: 2008-03-12T13:18:35Z
Registrar Registration Expiration Date: 2016-03-12T13:18:35Z
Registrar: GoDaddy.com, LLC
Registrar IANA ID: 146
Registrar Abuse Contact Email: [email protected]
Registrar Abuse Contact Phone: +1.4806242505
Domain Status: clientTransferProhibited http://www.icann.org/epp#clientTransferProhibited
Domain Status: clientUpdateProhibited http://www.icann.org/epp#clientUpdateProhibited
Domain Status: clientRenewProhibited http://www.icann.org/epp#clientRenewProhibited
Domain Status: clientDeleteProhibited http://www.icann.org/epp#clientDeleteProhibited
Registry Registrant ID:
Registrant Name: J Barraza
Registrant Organization: ExoticPetNetwork.com
Registrant Street: P.O. Box 7807
Registrant City: Redlands
Registrant State/Province: California
Registrant Postal Code: 92375
Registrant Country: United States
Registrant Phone: +1.9092556741
Registrant Phone Ext:
Registrant Fax:
Registrant Fax Ext:
Registrant Email: [email protected]
Registry Admin ID:
Admin Name: J Barraza
Admin Organization: ExoticPetNetwork.com
Admin Street: P.O. Box 7807
Admin City: Redlands
Admin State/Province: California
Admin Postal Code: 92375
Admin Country: United States
Admin Phone: +1.9092556741
Admin Phone Ext:
Admin Fax:
Admin Fax Ext:
Admin Email: [email protected]
Registry Tech ID:
Tech Name: J Barraza
Tech Organization: ExoticPetNetwork.com
Tech Street: P.O. Box 7807
Tech City: Redlands
Tech State/Province: California
Tech Postal Code: 92375
Tech Country: United States
Tech Phone: +1.9092556741
Tech Phone Ext:
Tech Fax:
Tech Fax Ext:
Tech Email: [email protected]
Name Server: NS0.DNSMADEEASY.COM
Name Server: NS1.DNSMADEEASY.COM
Name Server: NS2.DNSMADEEASY.COM
Name Server: NS3.DNSMADEEASY.COM
Name Server: NS4.DNSMADEEASY.COM
DNSSEC: unsigned
 

HereFishyFishy

Bearded Dragon Egg
Messages
15
Php and javascript are also being passed and processed in the user facing document, these should be limited in this area, and per-processed in a php render file so html is dynamic, so users can't see whats happening.
 
Status
Not open for further replies.
Top