docdoku / docdoku-plm

The project purpose is to develop a comprehensive, robust open source PLM (Product LifeCycle Management) solution.
http://www.docdokuplm.com
GNU Affero General Public License v3.0
241 stars 98 forks source link

Password visible when use wireshark #1178

Closed ludoBarel closed 6 years ago

ludoBarel commented 6 years ago

When i've analyzed TCP exchange for login process between client and server with wireshark, i've noticed than the password was visible with it's real value. According me i think it must be encrypted ? is it than normal it didn't encrypted ?

trace_login.pcapng.txt

To see content of shared file juste rename it trace_login.pcapng. Use tcp.port==8080 in filter field of wireshark to see only interesting data