A website that states “CrossLoop - Simple, secure screen-sharing and trusted experts for computer help”
is not very secure at all when you look at this picture.
When you login to the website over a secure encryption, it uses the GET method to log you in and shows your password and email to the world and people standing behind you.
I entered the email as email[at]jicola.com and the password as mypassword and the URL outputs “https://crossloop.com/quicklogin.htm?login_error=1&j_password=mypassword&q=y&j_username=email[at]jicola.com&qurl=”
For a website that exchanges money between clients and computer experts, showing a user name and password in the web browsers URL is not acceptable. Especially when the website is a gateway to allow two remote users to access and control each others computer. It will open the world up to hackers.
Crossloop has to do something about this and let your someone’s username and password to be shown in the URL. Even though the password is wrong, it only has to be one letter or number and standbyers can work out the correct password.
Update: This security flaw only happens when you click the log in link on the home page and the URL is http://crossloop.com/quicklogin.htm. To securely log in, use this link https://crossloop.com/login.htm. If you incorrectly log in on this URL, it shows login.htm?login_error=1, and not your email and password.
VN:F [1.4.2_694]
Rating: 0.0/5 (0 votes cast)