jeftsd / SmartHome

0 stars 0 forks source link

Signup interception vulnerability #3

Open eonsik opened 4 years ago

eonsik commented 4 years ago

On the signup page, the password input seems like it can be intercepted in the middle and changed to something else than the user intended.

pass1

@jeftsd @eonsik

jeftsd commented 4 years ago

Solution: force HTTPS on all server-client communications