password in URL for web server login?

Xeoma Software

Moderators: Admin_N, Administrator, Admin_P, Admin_K

password in URL for web server login?

Postby ace90210 » Sun Nov 04, 2018 1:16 pm

Hi everyone,
Im new to Xeoma and running it in a docker container on a server, i configured Xeoma to setup CCTV web server which works fine but i noticed the password is passed in the URL in plain text when logging in. There isnt any reason to do this (besides lazy development) and its extremely insecure even over HTTPS.

Have i missed a setting or is this intended behaviour? If so (intended) please Felenasoft in the nicest way possible hire someone who knows just about anything with regards to security over the web. with the password in the address bar people browser history not to mention many other forms of attack could be used to get into the CCTV system if the user isnt going out of there way to avoid falling into security wholes you left in for no good reason (just use the normal basic encrypted HTTP POST rest call like everyone else).

I must say seeing security software do a mistake i wouldnt expect a 1 year Junior developer to make relating to security does not fill me with much confidence the software is secure. :lol:
Attachments
cctv.png
cctv.png (13.46 KiB) Viewed 3300 times
ace90210
 
Posts: 1
Joined: Sun Nov 04, 2018 1:03 pm

Re: password in URL for web server login?

Postby skylord123 » Mon Nov 12, 2018 7:51 pm

That is pretty bad. On the bright side I don't think they support SSL so it shouldn't be any less secure than posting the data.

Their web client is a WIP as far as I am concerned. I don't use it because it is slow (reminds me of using zoneminder which was terrible). Nothing beats the performance of a native app.
skylord123
 
Posts: 32
Joined: Fri Jun 02, 2017 5:18 pm


Return to Xeoma - General discussion

Who is online

Users browsing this forum: No registered users and 17 guests