The verification of account details uses SSL but the site is not secured and no certificate verification is displayed. The site data with a path to the secure server is exposed in the HTML code in the scouce code.
Are the SID's rotated or static?
document.forms[0].action='https://secure.navyfield.com/UserAuth/Login.aspx?sid=*******************'
Note SID data removed.
|