Password in clear text in URL
When manually logging in to the helpdesk, the user password is exposed in clear text in the url is the address bar when the login fails. This is passed over the network, and visible on screen. This is rather insecure, as exposing passwords with minor typing errors in them give a very good clue to the correct password.
ie.:
"?j_username=testusername&j_password=TESTPASSWORD"
New to ADSelfService Plus?