Last modified: 2011-07-14 07:59:19 UTC
Created attachment 8781 [details] MSword file showing PoC for the bug Packet capture over the network using wireshark, reveals that wikipedia login credentials are passed over the network in clear text and can be seen by anybody monitoring the network.
Yes, Wikipedia uses http by default, which means there's no encryption of browser cookies. This allows anyone to hijack your session if they're able to obtain these cookies (via sniffing, etc.). This seems like a duplicate of bug 9816.
(In reply to comment #0) > reveals that wikipedia login > credentials are passed over the network in clear text and can be seen by > anybody monitoring the network. If people on the wmf cluster of projects want to, they can log into the secure cluster to prevent this[1]. [1]. https://secure.wikimedia.org/