Author Topic: HTTPS Fully up and running  (Read 2634 times)

0 Members and 2 Guests are viewing this topic.

Offline Stackprotector

  • Administrator
  • Titan
  • *
  • Posts: 2515
  • Cookies: 205
    • View Profile
HTTPS Fully up and running
« on: February 25, 2014, 12:27:42 am »
Hi guys,


Just wanted to note you that I have put up a valid SSL/TLS certificate and you are now more secure. In the coming days we will fine tune this for optimal security.


https://evilzone.org/ <---


Edit/Note:
Try removing external avatar's and upload them here. We might remove that feature in the near future.
« Last Edit: February 25, 2014, 12:39:44 am by Factionwars »
~Factionwars

Offline bluechill

  • Cybermancer
  • Royal Highness
  • ****
  • Posts: 682
  • Cookies: 344
  • I am the existence in these walls
    • View Profile
Re: HTTPS Fully up and running
« Reply #1 on: February 25, 2014, 02:15:22 am »
SMF doesn't work properly with SSL.  Also my cert was valid....
I have dreamed a dream, but now that dream has gone from me.  In its place now exists my own reality, a reality which I have created for myself by myself.

Offline proxx

  • Avatarception
  • Global Moderator
  • Titan
  • *
  • Posts: 2803
  • Cookies: 256
  • ФФФ
    • View Profile
Re: HTTPS Fully up and running
« Reply #2 on: February 25, 2014, 06:11:15 am »
SMF doesn't work properly with SSL.  Also my cert was valid....
https://evilzone.org/hacking-and-security/session-hijacking-evilzone/
I suppose you mean this ?

Anyway, thanks guys.


*edit*
Just verified that it indeed and as expected does not resolve the issue of sending unecrypted traffic.
« Last Edit: February 25, 2014, 06:58:39 am by proxx »
Wtf where you thinking with that signature? - Phage.
This was another little experiment *evillaughter - Proxx.
Evilception... - Phage

Offline Stackprotector

  • Administrator
  • Titan
  • *
  • Posts: 2515
  • Cookies: 205
    • View Profile
Re: HTTPS Fully up and running
« Reply #3 on: February 25, 2014, 11:52:33 am »
SMF doesn't work properly with SSL.  Also my cert was valid....
https://evilzone.org/hacking-and-security/session-hijacking-evilzone/
I suppose you mean this ?

Anyway, thanks guys.


*edit*
Just verified that it indeed and as expected does not resolve the issue of sending unecrypted traffic.

I think i can verify that my security policies fixed this. My wireshark does not pick up any HTTP trafic only HTTPS.
~Factionwars

Offline proxx

  • Avatarception
  • Global Moderator
  • Titan
  • *
  • Posts: 2803
  • Cookies: 256
  • ФФФ
    • View Profile
Re: HTTPS Fully up and running
« Reply #4 on: February 25, 2014, 12:14:03 pm »
I think i can verify that my security policies fixed this. My wireshark does not pick up any HTTP trafic only HTTPS.
I will recheck and post my findings tonight.
Thanks for the attention :)
« Last Edit: February 25, 2014, 12:14:31 pm by proxx »
Wtf where you thinking with that signature? - Phage.
This was another little experiment *evillaughter - Proxx.
Evilception... - Phage

Offline Stackprotector

  • Administrator
  • Titan
  • *
  • Posts: 2515
  • Cookies: 205
    • View Profile
Re: HTTPS Fully up and running
« Reply #5 on: February 25, 2014, 12:32:44 pm »
I will recheck and post my findings tonight.
Thanks for the attention :)
Also not that it might depend on a browsers https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security which is good against certain attack vectors and translates all local http links to https. Thanks!
~Factionwars

Offline bluechill

  • Cybermancer
  • Royal Highness
  • ****
  • Posts: 682
  • Cookies: 344
  • I am the existence in these walls
    • View Profile
Re: HTTPS Fully up and running
« Reply #6 on: February 25, 2014, 02:00:28 pm »
SMF also doesn't use SSL urls everywhere too so it will call non secure ones from http negating the point of SSL.  That's the reason we only up until now used my CA cert which was valid just not made by an authority other than the EvilZone Certificate signing authority.
I have dreamed a dream, but now that dream has gone from me.  In its place now exists my own reality, a reality which I have created for myself by myself.

Offline Stackprotector

  • Administrator
  • Titan
  • *
  • Posts: 2515
  • Cookies: 205
    • View Profile
Re: HTTPS Fully up and running
« Reply #7 on: February 25, 2014, 02:05:33 pm »
SMF also doesn't use SSL urls everywhere too so it will call non secure ones from http negating the point of SSL.  That's the reason we only up until now used my CA cert which was valid just not made by an authority other than the EvilZone Certificate signing authority.
That's why i used HSTS.
~Factionwars

Offline kenjoe41

  • Symphorophiliac Programmer
  • Administrator
  • Baron
  • *
  • Posts: 990
  • Cookies: 224
    • View Profile
Re: HTTPS Fully up and running
« Reply #8 on: February 25, 2014, 02:16:36 pm »
just imagine my horror on my first use of a commandline browser (lynx) and it redirects me to https://evilzone.org.
And am like "What?", Is something wrong or does this browser forcefully use ssl. Anyway, now i see their is nothing wrong.
Thanks guys.
If you can't explain it to a 6 year old, you don't understand it yourself.
http://upload.alpha.evilzone.org/index.php?page=img&img=GwkGGneGR7Pl222zVGmNTjerkhkYNGtBuiYXkpyNv4ScOAWQu0-Y8[<NgGw/hsq]>EvbQrOrousk[/img]

Offline bluechill

  • Cybermancer
  • Royal Highness
  • ****
  • Posts: 682
  • Cookies: 344
  • I am the existence in these walls
    • View Profile
Re: HTTPS Fully up and running
« Reply #9 on: February 25, 2014, 04:57:05 pm »
That's why i used HSTS.

I didn't realize you were using hsts but since you configured it that way, that should be fine.
I have dreamed a dream, but now that dream has gone from me.  In its place now exists my own reality, a reality which I have created for myself by myself.

Offline proxx

  • Avatarception
  • Global Moderator
  • Titan
  • *
  • Posts: 2803
  • Cookies: 256
  • ФФФ
    • View Profile
Re: HTTPS Fully up and running
« Reply #10 on: February 25, 2014, 06:49:56 pm »
Could not reproduce it thus far.
Firefox still gives a message about unencrypted traffic at times.

Thanks for fixing that Factionwars.

Will check again :)
« Last Edit: February 25, 2014, 09:57:34 pm by proxx »
Wtf where you thinking with that signature? - Phage.
This was another little experiment *evillaughter - Proxx.
Evilception... - Phage

Offline Axon

  • VIP
  • King
  • *
  • Posts: 2047
  • Cookies: 319
    • View Profile
Re: HTTPS Fully up and running
« Reply #11 on: March 01, 2014, 01:24:25 pm »
This what I have been waiting for a long time. Thank you Factionwars :D

Offline Kulverstukas

  • Administrator
  • Zeus
  • *
  • Posts: 6627
  • Cookies: 542
  • Fascist dictator
    • View Profile
    • My blog
Re: HTTPS Fully up and running
« Reply #12 on: March 01, 2014, 01:57:04 pm »
For the love of GOD DISABLE forced SSL. Shit's so cray! I always get this stupid warning everytime I try to do something: https://support.mozilla.org/en-US/questions/964250

among other really stupid problems like page refreshing itself when I press the back button - WTF!!, fuckin' christ.

Offline proxx

  • Avatarception
  • Global Moderator
  • Titan
  • *
  • Posts: 2803
  • Cookies: 256
  • ФФФ
    • View Profile
Re: HTTPS Fully up and running
« Reply #13 on: March 01, 2014, 02:52:15 pm »
That is still better than sending everything in the fucking clear although I can understand the discomfort.
Funny because I use FF and have just but a few warnings here and there.
« Last Edit: March 01, 2014, 02:53:00 pm by proxx »
Wtf where you thinking with that signature? - Phage.
This was another little experiment *evillaughter - Proxx.
Evilception... - Phage

Offline I_Learning_I

  • Knight
  • **
  • Posts: 267
  • Cookies: 26
  • Nor black or white, not even grey. What hat am I?
    • View Profile
    • Hacking F0r Fr33
Re: HTTPS Fully up and running
« Reply #14 on: March 03, 2014, 01:10:04 am »
Even without wireshark or anything Mr Google Chrome is telling me there's non secure data being transferred.
Doesn't accuse any problem with certification tho.
« Last Edit: March 03, 2014, 01:10:33 am by I_Learning_I »
Thanks for reading,
I_Learning_I