Whistlelink: Site-access password exposed in web server access logs via GET query string
Posted by Red Nanaki via Fulldisclosure on Jul 02Whistlelink: Site-access password exposed in web server access logs via GET
query string Severity: CRITICAL SUMMARY The Whistlelink reporting portal protects optionally-enabled, password-gated
whistleblowing sites with a site-access password. When a visitor unlocks such a
site, the client validates the password by issuing an HTTP GET request that
carries the password as a URL query-string parameter: GET...