Last modified: 2011-07-14 07:59:19 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T31893, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 29893 - Login credentials over network in Clear-text
Login credentials over network in Clear-text
Status: RESOLVED INVALID
Product: Wikimedia
Classification: Unclassified
General/Unknown (Other open bugs)
unspecified
PC Windows XP
: Unprioritized critical (vote)
: ---
Assigned To: Nobody - You can work on this!
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2011-07-14 07:33 UTC by 3psil0nlambda
Modified: 2011-07-14 07:59 UTC (History)
3 users (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments
MSword file showing PoC for the bug (294.27 KB, application/vnd.openxmlformats-officedocument.wordprocessingml.document)
2011-07-14 07:33 UTC, 3psil0nlambda
Details

Description 3psil0nlambda 2011-07-14 07:33:26 UTC
Created attachment 8781 [details]
MSword file showing PoC for the bug

Packet capture over the network using wireshark, reveals that wikipedia login credentials are passed over the network in clear text and can be seen by anybody monitoring the network.
Comment 1 MZMcBride 2011-07-14 07:41:47 UTC
Yes, Wikipedia uses http by default, which means there's no encryption of browser cookies. This allows anyone to hijack your session if they're able to obtain these cookies (via sniffing, etc.). This seems like a duplicate of bug 9816.
Comment 2 p858snake 2011-07-14 07:43:19 UTC
(In reply to comment #0)
>  reveals that wikipedia login
> credentials are passed over the network in clear text and can be seen by
> anybody monitoring the network.

If people on the wmf cluster of projects want to, they can log into the secure
cluster to prevent this[1].

[1]. https://secure.wikimedia.org/

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links