|
|
|
|
|
by mercurial
4479 days ago
|
|
Somebody is trying to outshine Mt. Gox in terms of amateurism. I wouldn't be surprised to find a number of other vulnerabilities (SQL injection ?). Who the hell thinks it's OK to store non-encrypted passwords in this day and age? It's not like you don't have a major security breach every month... Also, I like the 'handler.php' endpoint returning some kind of ugly pseudo-SOAP. Ugh. |
|
...and an amazing number of finance organisations who can't handle non alpha-numeric characters in passwords, indicating failure to hash.