网易登录是在自欺欺人吗? - V2EX
FrankFang128

网易登录是在自欺欺人吗?

  •  1
     
  •   FrankFang128 Aug 27, 2017 4852 views
    This topic created in 3196 days ago, the information mentioned may be changed or developed.
    1. https://mail.163.com/ 会强行跳转到 http
    2. 页面上显示「正使用 SSL 登录」,然而只是在 http 页面里面用了一个 https 的 iframe
    3. 攻击者只要篡改 http 页面,即可轻易伪造登录框

    所以,网易的同学为什么不在 mail.163.com 开启 https 访问?

    8 replies    2017-10-09 23:39:26 +08:00
    zrt
        1
    zrt  
       Aug 27, 2017
    好像 https://mail.163.com/ 可以用,就是广告加载不出来?
    FrankFang128
        2
    FrankFang128  
    OP
       Aug 27, 2017
    我打开直接变成 http
    @zrt
    zsj950618
        3
    zsj950618  
       Aug 27, 2017
    所以为什么还要用网易邮箱?
    solidsnake
        4
    solidsnake  
       Aug 27, 2017 via iPhone
    网易用的老流氓的证书
    FrankFang128
        5
    FrankFang128  
    OP
       Aug 27, 2017
    @zsj950618 只是想嘲讽一下网易的开发。我用 Gmail + QQ
    Hardrain
        6
    Hardrain  
       Aug 28, 2017
    网易邮箱登录时的 POST 包似乎走了 SSL

    但是这种页面本身用 http 且还有走 http 的 JS 的
    一被注入岂不完蛋
    明文的凭据都能获取到吧
    benjix
        7
    benjix  
       Oct 9, 2017
    FrankFang128
        8
    FrankFang128  
    OP
       Oct 9, 2017
    @benjix 有不安全的脚本
    About     Help     Advertise     Blog     API     FAQ     Solana     3228 Online   Highest 6679       Select Language
    创意工作者们的社区
    World is powered by solitude
    VERSION: 3.9.8.5 37ms UTC 13:11 PVG 21:11 LAX 06:11 JFK 09:11
    Do have faith in what you're doing.
    ubao msn snddm index pchome yahoo rakuten mypaper meadowduck bidyahoo youbao zxmzxm asda bnvcg cvbfg dfscv mmhjk xxddc yybgb zznbn ccubao uaitu acv GXCV ET GDG YH FG BCVB FJFH CBRE CBC GDG ET54 WRWR RWER WREW WRWER RWER SDG EW SF DSFSF fbbs ubao fhd dfg ewr dg df ewwr ewwr et ruyut utut dfg fgd gdfgt etg dfgt dfgd ert4 gd fgg wr 235 wer3 we vsdf sdf gdf ert xcv sdf rwer hfd dfg cvb rwf afb dfh jgh bmn lgh rty gfds cxv xcv xcs vdas fdf fgd cv sdf tert sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf shasha9178 shasha9178 shasha9178 shasha9178 shasha9178 liflif2 liflif2 liflif2 liflif2 liflif2 liblib3 liblib3 liblib3 liblib3 liblib3 zhazha444 zhazha444 zhazha444 zhazha444 zhazha444 dende5 dende denden denden2 denden21 fenfen9 fenf619 fen619 fenfe9 fe619 sdf sdf sdf sdf sdf zhazh90 zhazh0 zhaa50 zha90 zh590 zho zhoz zhozh zhozho zhozho2 lislis lls95 lili95 lils5 liss9 sdf0ty987 sdft876 sdft9876 sdf09876 sd0t9876 sdf0ty98 sdf0976 sdf0ty986 sdf0ty96 sdf0t76 sdf0876 df0ty98 sf0t876 sd0ty76 sdy76 sdf76 sdf0t76 sdf0ty9 sdf0ty98 sdf0ty987 sdf0ty98 sdf6676 sdf876 sd876 sd876 sdf6 sdf6 sdf9876 sdf0t sdf06 sdf0ty9776 sdf0ty9776 sdf0ty76 sdf8876 sdf0t sd6 sdf06 s688876 sd688 sdf86