CheckEmoji Community · the emoji forum
🏠 Home 🆕 What's new ❓ Unanswered 🔥 Popular 📡 RSS Members 👥 0 online log in · register
Home › Miscellaneous › Feedback & Suggestions › Potential security issue when logging in to the forum

Potential security issue when logging in to the forum

Started by Jack Cook7 · · 👁 4 views · 14 replies

📡 Subscribe to replies

Participants Jack Cook7ambermason16Sam Green73Sandra Parker3Alex Cookcasualharbor9hollowtrucker77cosmicskipper39Benjamin King2shadowseal12
Jack Cook7 Jack Cook7 RegularOP
376 messages
joined Aug 2017
#1 ·
So, I’ve noticed this weird thing happening a few times now when I try to sign in to the forum. Usually, the first attempt just fails, and then it works perfectly on the second try.

Since the login is going through plain HTTP, you guys might be sitting ducks for a man-in-the-middle attack. Seriously, it's a bit sketchy.

I just had this happen tonight, Monday the 8th, right around 11:55 PM, so feel free to dig through the logs and check out those failed attempts.

☕
ambermason16 ambermason16 Active Member
213 messages
joined Apr 2009
#2 ·
That happens to me every now and then too.. 🤷

Anyway, I’m logging back in now.. 😁

And what exactly would a man-in-the-middle attack even look like here? 🍿
Sam Green73 Sam Green73 Active Member
144 messages
joined Aug 2018
#3 ·
ambermason16 said:So, what exactly does a man-in-the-middle attack look like?

It’s basically how they snag your password.
Imagine there's this fake website designed to look exactly like a legitimate forum. You go there, you enter your login info thinking everything is fine, and then they redirect you to the actual site. But here's the catch: while you were being "redirected," they already logged your credentials on their end.

Personally, I don't think that's what happened in this case.
ambermason16 ambermason16 Active Member
213 messages
joined Apr 2009
#4 ·
Sam Green73 said:How they snatch passwords.
They set up a fake site that looks just like a forum, you log in, they redirect you to the actual forum, but they’ve already logged your password in the background.

I doubt that's what happened here.

Good grief! My millions are at risk because my forum password isn't secure enough!!! I demand an immediate explanation and full compensation from the admins, the owners of unknown, the President, and the CEO of the entire Internet! 😁
Sandra Parker3 Sandra Parker3 Regular
419 messages
joined Oct 2007
#5 ·
Jack Cook7 said:I've noticed a few times now that when I try to log into Reddit, it doesn't work on the first try. Usually, it goes through on the second attempt....

I think there was already a thread about this somewhere, but I can't remember what the consensus was.

As for me, I can't even get logged in; usually, when it fails, I have to try about 5, 6, 7, or 8 times before it finally sticks.

Sam Green73 said:How passwords are collected.
There's this site.....

Wait, why isn't this using the HTTPS protocol???

ambermason16 said:Good grief! My millions are in serious danger because of this forum password!!! I demand an explanation and compensation from the admins, the owner of unknown, the President, and the Director of the Internet! 😁

Typical off-topic rambling, as usual.
Alex Cook Alex Cook Active Member
157 messages
joined May 2009
#6 ·
Sandra Parker3 said:nah... I can't even get logged in, and usually when it doesn't work right away, it takes like five, six, seven, eight tries before it finally sticks

The same thing happens to me whenever I'm at the office. Even after I log out and clear my cookies and all that other junk, I'll come back the next day and find myself already logged into Reddit without doing anything... 😕

And no, I don't have CCleaner or any of those tools—I'm not allowed to download random apps on my work machine. 🙂
casualharbor9 casualharbor9 Active Member
168 messages
joined Feb 2010
#7 ·
Sam Green73 said:The method they use to harvest passwords.
They set up a fake landing page that looks just like a legitimate forum. You think you're logging in, but once you hit submit, they redirect you to the actual site while simultaneously logging your credentials on their end.
...

... something like that?

example-site.com/index.php?
Sam Green73 Sam Green73 Active Member
144 messages
joined Aug 2018
#8 ·
casualharbor9 said:... something like that?

example-server.com/index.php?

I'm assuming "lb" is just shorthand for load balancing.
hollowtrucker77 hollowtrucker77 Regular
681 messages
joined Nov 2007
#9 ·
yup
cosmicskipper39 cosmicskipper39 Active Member
71 messages
joined Jan 2012
#10 ·
Is this lb.orbis.hr link glitching out at the exact same time as Reddit? 🤔
Benjamin King2 Benjamin King2 Active Member
138 messages
joined Apr 2007
#11 ·
Sandra Parker3 said:And why isn't it using the HTTPS protocol???

Because there’s honestly zero need for it—we aren't running any credit card transactions or handling sensitive data here... and since SSL certificates actually cost money, unless you're looking to pay a premium just to browse the forum, we'll stick to this. 🙂
ambermason16 ambermason16 Active Member
213 messages
joined Apr 2009
#12 ·
Sandra Parker3 said:Just stay on topic here, following the usual rules...

Oh, give me a break with the drama... seriously, who actually gives a damn about your password, my password, or anyone else's? You act like some massive terrorist organization is going to launch a high-tech cyberattack just to figure out if you’re logging into Reddit as "butterfly1" or "butterfly2." It's ridiculous. ☕

It's just a glitch... nothing more, nothing less.
shadowseal12 shadowseal12 Newcomer
6 messages
joined Aug 2010
#13 ·
Man, everyone's stressing about MITM attacks, but they're running vBulletin 384. I’d bet my bottom dollar an xss exploit would slide right through without anyone even noticing.
Sandra Parker3 Sandra Parker3 Regular
419 messages
joined Oct 2007
#14 ·
Benjamin King2 said:...SSL certs aren't free, so do you want to start paying just to access the forum? 🙂

Why on earth would I pay for forum access? 🤷

I don't even pay Google for Gmail.
hollowtrucker77 hollowtrucker77 Regular
681 messages
joined Nov 2007
#15 ·
Alright, I think we can finally consider the security issue settled here.
Honestly, people who aren't sharp enough to grasp why passwords even exist are just going to keep running into walls and acting shocked when their accounts get hijacked.
Maybe, if we're lucky, they'll eventually decide to actually listen to the mountain of advice out there on how to stay safe online.

You must log in or register to reply here.

Log in Register

🔗 Similar threads