Ascended password in URL

Locked
Sphinx42
Goa'uld
Posts: 1480
Joined: Fri Sep 08, 2006 7:02 am
ID: 0

Ascended password in URL

Today, I mistyped my password on Ascended (again); thing happens, especially if you wake up too early. Anyway, this time around I thought I'd ask about something I noticed the last time I did the same mistake.
The login and password you have entered (name/email/pass - Preem Palver/[edited]/[edited]) do not match.
Try to retype them again.
If you had a quote in your name, it has been replaced by a dash (-)

The same thing appears in the URL:

Code: Select all

http://ascended.gatewars.com/index.php?strErr=The%20login%20and%20password%20you%20have%20entered%20%28name/email/pass%20-%20Preem%20Palver/[edited]/[edited]%29%20do%20not%20match.%3Cbr%3E%20Try%20to%20retype%20them%20again.%20%20%3Cbr%3EIf%20you%20had%20a%20quote%20in%20your%20name,%20it%20has%20been%20replaced%20by%20a%20dash%20%28-%29

I'm not sure it was done like this on purpose, but since it shows up in the URL, it also shows up in my Firefox history. So, the possibility exists (however remote) that someone could gain access to my laptop and, seeing the mistyped password, guess the real one and log in to my Ascended account (and possibly others if I were to use the same password on multiple sites/servers). Or, on second thought, that someone could see the red text over your shoulder - which kinda defeats the purpose of the password field.

Before anyone suggests, I do have a fairly strong password and it's different from any other password I use; also, I've deleted the URL from my history just to be sure. Still, I think this could be an issue for others, and the advantage of seeing what you've mistyped is outweighed by the chance of someone else being able to see it.
Gone, left, no longer here.
Lithium
Forum Zombie
Posts: 6085
Joined: Wed Jun 27, 2007 11:34 pm
Alliance: The Pirate's Panties
Race: Pirate
ID: 0
Location: Pantie's Island
Contact:

Re: Ascended password in URL

try to login correctly and see if psw is in yr url. if not then its fine. also if smone breaks into yr house and steal yr laptop then dont call admin :)
Image
Previously on GateWars Forum
The orgin of Guild
Spoiler
Lithium wrote:he was talkin bout me and remembering the days i was massing him wit one finger ;)
Guild wrote:is that the same finger you stick up your bum ? :smt060
Lithium wrote:no its the one who gave u life ;)
Field Marshall wrote:Lith put his finger up his bum and Guild arrived? :smt017
I wish that was genuinely true :)
Lithium wrote:oooo why there isnt any emo for this one , id have dropped of chair dead :smt042
MajorLeeHurts wrote:
Lithium wrote:oooo why there isnt any emo for this one , id have dropped of chair dead :smt042
Agreed that was the funnies **Filtered** ive read here!
Im sure JT is enjoying this thread , if he isnt hes in a coma !
Feedback Me
http://stargatewars.herebegames.com/vie ... 8&t=101259
stuff of legends
Forum Expert
Posts: 1217
Joined: Sat May 23, 2009 1:50 am
Alliance: The Legion
Location: China Beijing

Re: Ascended password in URL

Preem Palver wrote:I'm not sure it was done like this on purpose, but since it shows up in the URL, it also shows up in my Firefox history. So, the possibility exists (however remote) that someone could gain access to my laptop and, seeing the mistyped password, guess the real one and log in to my Ascended account (and possibly others if I were to use the same password on multiple sites/servers). Or, on second thought, that someone could see the red text over your shoulder - which kinda defeats the purpose of the password field.

If someone managed to access your comp then the history of sgw would be the last thing you would want to worry about. If you are so worried use chromes incognito or go wipe your history, cache, and cookies every so often.
Yes its probably not one of admins brightest moments with sending and receiving sensitive info and then echo'ing it back, but its hardly a high stake. Now you know it exists you can hide it from the publics view when you enter it.
Image
Image
Sarevok
Forum Addict
Posts: 4042
Joined: Wed May 09, 2007 7:42 pm
Race: NanoTiMaster
ID: 0

Re: Ascended password in URL

I suppose it couldn't hurt to just not send back the invalid information, just say "It's wrong, try again".

Also, there are people that access it at public location, to which someone maybe able to login.
viewtopic.php?f=13&t=162732
Suggestions, Comments please :)
R8 wrote:TEAM WORK WILL BEAT $$ ANYDAY OF THE WEEK
angel wrote:Except the payday [-X
12agnar0k wrote:Also it's still not a war game, you have att/def weps yes, but you also have uu and UP, does this mean its a sex game, oh no, XRATEDSGW, THIS GAME IS PORN!
Ban Admin
<+CABAL> so adminHere, ever thought about playing SGW? :b
<~adminHere> cabal - i do :)
<+CABAL> :o
<+Sarevok> Cabal, look up Jtest ;)
<~adminHere> no -not jtest
<~adminHere> another :) i am a multi ;)
<+Sarevok> :O
* +CABAL screens
<+CABAL> :b
* +Sarevok Ban's Admin
Sphinx42
Goa'uld
Posts: 1480
Joined: Fri Sep 08, 2006 7:02 am
ID: 0

Re: Ascended password in URL

Lithium wrote:try to login correctly and see if psw is in yr url. if not then its fine. also if smone breaks into yr house and steal yr laptop then dont call admin :)


Of course, it isn't - otherwise, I would have posted about that. It's not the correct password, but it is almost the correct one - and while I don't use simple words or phrases in my passwords, others do. And, of course, admin will not be the one I'll call if someone steals my laptop - but that doesn't mean I shouldn't post here, if nothing else, to make sure it isn't something he may have forgotten to change (seeing how Ascended has been updated less regularly than Main).


stuff of legends wrote:If someone managed to access your comp then the history of sgw would be the last thing you would want to worry about.


:roll: I don't care much about my browser history (or my Ascended account, to be honest), I was just trying to help prevent it from happening to others - and, given enough time, someone will come complaining that their Ascended account was 'hacked', and this could be one of the reasons.

stuff of legends wrote:If you are so worried use chromes incognito or go wipe your history, cache, and cookies every so often.
[...] Now you know it exists you can hide it from the publics view when you enter it.


I don't want to quote my first post, so I'll just say that yes, I do know about it and what to do to avoid it (not to mention that it is unlikely anyone would have access to it) - but others might not. If one newbie will read this and understand it and learn something new, it will have been worth posting it.


Sarevok wrote:Also, there are people that access it at public location, to which someone maybe able to login.


Exactly - while there isn't much of a chance of anyone going through my history on my laptop and I don't even think there are more than a couple of people in my city who play GW (and those I know quite well), it could be an issue for people in other places, so I thought I'd point this out, since I didn't find anything about it anywhere.
Gone, left, no longer here.
Locked

Return to “For Admin Archives”