bajzarpa / hoverzoom

Automatically exported from code.google.com/p/hoverzoom
1 stars 0 forks source link

HTTPS Stripping... #365

Open GoogleCodeExporter opened 9 years ago

GoogleCodeExporter commented 9 years ago
Hey.

On HTTPS sites, it seems like it loads something from 
http://hoverzoom.net/api/amazon/getlinks/?kw=[something].

Problem here is that it loads it over HTTP. If I were to be 
Man-In-The-Middle'd, they could intercept and edit the data sent here.

Please get a valid SSL cert for hoverzoom.net, or at least load this API over 
HTTPS.

Thank you.

Original issue reported on code.google.com by Sir....@gmail.com on 5 Oct 2012 at 5:29