Security Issues with BHW?

Discussion in 'BlackHat Lounge' started by Georgebg, Mar 21, 2014.

  1. Georgebg

    Georgebg Elite Member

    Joined:
    Dec 2, 2009
    Messages:
    1,681
    Likes Received:
    775
    e4761ce187.png

    /Discuss
     
  2. Apricot

    Apricot Administrator Staff Member

    Joined:
    Mar 26, 2013
    Messages:
    14,078
    Likes Received:
    9,377
    Gender:
    Female
    Occupation:
    BHW Admin
    Location:
    Station 2E
    Home Page:
    Aweber is to do with the newsletter signup forms. By loading BHW, you load their forms from wherever they are. It's nothing to worry about.

    Aweber are a genuine email maketing company.
     
  3. Georgebg

    Georgebg Elite Member

    Joined:
    Dec 2, 2009
    Messages:
    1,681
    Likes Received:
    775
    Yeah, I know Aweber are a legit company I was just supprised that my login will be sent to them, and this is something thats been happening for the last 2-3 days thats why I thought it was a bit odd.
     
  4. Grizzy

    Grizzy Senior Member

    Joined:
    Nov 11, 2008
    Messages:
    919
    Likes Received:
    1,001
    That's just lastpass being sloppy.

    You can't POST to a html forum and have your login creds leaked in that manner.

    If in doubt analyze the http headers. You'll see nothing important is passed to aweber.