davidv1992 / madmin

WIP
MIT License
1 stars 3 forks source link

Use POST instead of GET for login #31

Open mrngm opened 8 years ago

mrngm commented 8 years ago

From the logs:

gmulder@lilo4:/www/madmin/live/logs
$ zgrep login access.log-20160109.gz.
131.174.30.57 madmin.science.ru.nl - - [08/Jan/2016:17:14:43 +0100] "GET /login?username=redacted&password=hunter2 HTTP/1.1" 200 157 "-" "-"

This leaks passwords to anyone who has access to the logs.