<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:blogger='http://schemas.google.com/blogger/2008' xmlns:georss='http://www.georss.org/georss' xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-4521309719030850665</id><updated>2024-11-08T23:35:56.048+08:00</updated><category term="PlainPass"/><category term="Taiwan"/><category term="Shopping"/><category term="Ticket"/><category term="Submission"/><category term="DNS"/><category term="Travel"/><category term="Article"/><category term="Forward"/><category term="Government"/><category term="China"/><category term="Edu"/><category term="Hacked"/><category term="Telecom"/><category term="Announcement"/><category term="Game"/><category term="Hosting"/><category term="Product"/><title type='text'>我的密碼沒加密</title><subtitle type='html'>I&#39;m proud that I store my password in plaintext.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://plainpass.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default?redirect=false'/><link rel='alternate' type='text/html' href='http://plainpass.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default?start-index=26&amp;max-results=25&amp;redirect=false'/><author><name>Allen Own</name><uri>http://www.blogger.com/profile/07432128723498860159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgOTtJR54trZACfSZ1S-GfX8dHsYH3aLjRW6yUlr-mhSJ5cHFa2f0iPvaOYEB_AGShQpwl0tFbllzbdVooCPAh2wXx0OaEUOP6mdEB5n-yOUmnDwJC4LQ2gHlp7I4Z4Lk/s220/A2.png'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>67</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-4521309719030850665.post-6633099911943140519</id><published>2014-02-11T22:32:00.000+08:00</published><updated>2014-02-11T22:32:30.713+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="DNS"/><category scheme="http://www.blogger.com/atom/ns#" term="PlainPass"/><category scheme="http://www.blogger.com/atom/ns#" term="Taiwan"/><title type='text'>「hidomain 申大巨網數據服務中心」密碼沒加密！</title><content type='html'>DNS 系列第五篇！&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://hidomain.tw/&quot; target=&quot;_blank&quot;&gt;申大巨網&lt;/a&gt;成立於 2006 年，hidomain 跟其他同類型廠商一樣提供了網域名稱註冊、虛擬主機、VPS 主機、郵件代管等等。&lt;br /&gt;
&lt;br /&gt;
網站上沒有看到跟資訊安全有關的資訊，所以我們只好自己動手來看啦！&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhDIytDFqINw6xOcmSSWNeZIIQ0vr5aNgx3IhgRzhX7-ogdQkkimzKVSx1mXmxJY5keL9eFmWqtmiXA64rkaTfXna6dRA_Nk87n04urMp_WBx6cgMTSuTdZ-_VflXIOJQjkfVwp323lzKI/s1600/hidomain_00.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhDIytDFqINw6xOcmSSWNeZIIQ0vr5aNgx3IhgRzhX7-ogdQkkimzKVSx1mXmxJY5keL9eFmWqtmiXA64rkaTfXna6dRA_Nk87n04urMp_WBx6cgMTSuTdZ-_VflXIOJQjkfVwp323lzKI/s1600/hidomain_00.png&quot; height=&quot;482&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
首先我們點一下「登錄」...&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiWWesY_4XGW_sT2Fbo3y4eb9E533khAZ6A2sQn0Toi4RfxZT2KYdPbzg1Vp4y94Gtd2_E1shfP9ev3oZbEoY6LWTGHn72ep4FtxrxM3KWXespco5-J_kYU40ngbJtJQUkCYh-PhBXT5Y8/s1600/hidomain_01.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiWWesY_4XGW_sT2Fbo3y4eb9E533khAZ6A2sQn0Toi4RfxZT2KYdPbzg1Vp4y94Gtd2_E1shfP9ev3oZbEoY6LWTGHn72ep4FtxrxM3KWXespco5-J_kYU40ngbJtJQUkCYh-PhBXT5Y8/s1600/hidomain_01.png&quot; height=&quot;482&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
全劇終？&lt;br /&gt;
&lt;br /&gt;
我不清楚這個登錄是什麼狀況... 因此以下我們使用網友投稿的頁面來撰寫。&lt;br /&gt;
&lt;br /&gt;
首先註冊一個帳號：&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjrNV42r8IfEyZOU-mw1vhX35PLuE9xhcA76zzj2AFlF99AeWdutIZXVOawp1VIrVdYxw40FB_EFk7giy2P7CeFxvjraA14omd0oXh5RCpn82ZyF41Z2O4oczyzJRD1OuMilw7QIeep42c/s1600/hidomain_02.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjrNV42r8IfEyZOU-mw1vhX35PLuE9xhcA76zzj2AFlF99AeWdutIZXVOawp1VIrVdYxw40FB_EFk7giy2P7CeFxvjraA14omd0oXh5RCpn82ZyF41Z2O4oczyzJRD1OuMilw7QIeep42c/s1600/hidomain_02.png&quot; height=&quot;562&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
然後我們直接點選「忘記密碼」。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEieSTK7VUoKuYz6Iju1YwAaUBKZq3I7VNHaSqtcgLW0gZ1iCzxlXJj7TiZgblWsu7OBH8RCplnVH8I2Ph4cgmsKq2a7MpAIE1mY70I_MW3B3fRwvdNThoZk38IciOvpTZYzPpUCi1V-Wgg/s1600/hidomain_03.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEieSTK7VUoKuYz6Iju1YwAaUBKZq3I7VNHaSqtcgLW0gZ1iCzxlXJj7TiZgblWsu7OBH8RCplnVH8I2Ph4cgmsKq2a7MpAIE1mY70I_MW3B3fRwvdNThoZk38IciOvpTZYzPpUCi1V-Wgg/s1600/hidomain_03.png&quot; height=&quot;504&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
結果信箱中卻收到了原始登入的帳號密碼。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh8NObtSdDHaniYmuT6GswyFJg3rfyy3mDx-0KCfhcvrp9bmc6BqxM_drLUuMy8XF1NnA3jjoTMB2SOmTx07jxkfoQV4TVAMHpmvUl-WC7ORFCkO2i8PfLj-P_CSSlNgulIZcC8UuJ8sxQ/s1600/hidomain_04.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh8NObtSdDHaniYmuT6GswyFJg3rfyy3mDx-0KCfhcvrp9bmc6BqxM_drLUuMy8XF1NnA3jjoTMB2SOmTx07jxkfoQV4TVAMHpmvUl-WC7ORFCkO2i8PfLj-P_CSSlNgulIZcC8UuJ8sxQ/s1600/hidomain_04.png&quot; height=&quot;640&quot; width=&quot;622&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
廠商們加油吧！&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;
&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;「hidomain 申大巨網數據服務中心」密碼沒加密！&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
日期：2014-02-09&lt;br /&gt;
名稱：hidomain 申大巨網數據服務中心&lt;br /&gt;
網址：&lt;a href=&quot;http://hidomain.tw/&quot;&gt;http://hidomain.tw/&lt;/a&gt;&lt;br /&gt;
結果：密碼沒加密
&lt;br /&gt;
&lt;br /&gt;
感謝 Anonymous 的投稿！</content><link rel='replies' type='application/atom+xml' href='http://plainpass.com/feeds/6633099911943140519/comments/default' title='張貼留言'/><link rel='replies' type='text/html' href='http://plainpass.com/2014/02/hidomain-stores-passwords-in-plaintext.html#comment-form' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/6633099911943140519'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/6633099911943140519'/><link rel='alternate' type='text/html' href='http://plainpass.com/2014/02/hidomain-stores-passwords-in-plaintext.html' title='「hidomain 申大巨網數據服務中心」密碼沒加密！'/><author><name>Allen Own</name><uri>http://www.blogger.com/profile/07432128723498860159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgOTtJR54trZACfSZ1S-GfX8dHsYH3aLjRW6yUlr-mhSJ5cHFa2f0iPvaOYEB_AGShQpwl0tFbllzbdVooCPAh2wXx0OaEUOP6mdEB5n-yOUmnDwJC4LQ2gHlp7I4Z4Lk/s220/A2.png'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhDIytDFqINw6xOcmSSWNeZIIQ0vr5aNgx3IhgRzhX7-ogdQkkimzKVSx1mXmxJY5keL9eFmWqtmiXA64rkaTfXna6dRA_Nk87n04urMp_WBx6cgMTSuTdZ-_VflXIOJQjkfVwp323lzKI/s72-c/hidomain_00.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4521309719030850665.post-4898635860241044179</id><published>2014-01-23T13:19:00.000+08:00</published><updated>2014-01-23T18:54:49.383+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="DNS"/><category scheme="http://www.blogger.com/atom/ns#" term="PlainPass"/><category scheme="http://www.blogger.com/atom/ns#" term="Taiwan"/><title type='text'>「網路中文」密碼沒加密！</title><content type='html'>DNS 系列第四篇！&lt;br /&gt;
&lt;br /&gt;
「&lt;a href=&quot;http://www.net-chinese.com.tw/&quot; target=&quot;_blank&quot;&gt;網路中文&lt;/a&gt;」同為國內知名的網域名稱註冊商，成立於 2000 年，為首批 TW 域名註冊商。網站上除了註冊網域名稱之外，同時也有代管、網站建置、虛擬主機等服務。&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;https://web.archive.org/web/20031008094250/http://www.net-chinese.com.tw/&quot; target=&quot;_blank&quot;&gt;從 2003 年開始就長這個樣子&lt;/a&gt;的老牌網站，到底密碼的機制會怎麼設計呢？&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhMvfz-R-OJXabMmyxHlNj-purdd4FuQBd8qwnEuQHZMKcO2zX0cIM0ZLMruHx1SFtDbA37GayC5h4F9MfbsLU8JvGY0LwmihjqDW9wR17ZcDo_F7k2jZCmxItbNJLXz7wafrK8aV1DUf4/s1600/net-chinese_01.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhMvfz-R-OJXabMmyxHlNj-purdd4FuQBd8qwnEuQHZMKcO2zX0cIM0ZLMruHx1SFtDbA37GayC5h4F9MfbsLU8JvGY0LwmihjqDW9wR17ZcDo_F7k2jZCmxItbNJLXz7wafrK8aV1DUf4/s1600/net-chinese_01.png&quot; height=&quot;478&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
首先我們註冊一組帳號，註冊「多國域名管理」。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhRMW00jXuBCzzB7YGmr8kFIInJuTDfr0o0li-g0lVf06Rp8K1gFZB8wZ4zomuZczofc36novx8hv3zLJo__3DVIBFQSCVB-MIAgWBxddNzDqsH7M_c0Y8VI-jUK8d5vYWSFUmboCg6F7E/s1600/net-chinese_02.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhRMW00jXuBCzzB7YGmr8kFIInJuTDfr0o0li-g0lVf06Rp8K1gFZB8wZ4zomuZczofc36novx8hv3zLJo__3DVIBFQSCVB-MIAgWBxddNzDqsH7M_c0Y8VI-jUK8d5vYWSFUmboCg6F7E/s1600/net-chinese_02.png&quot; height=&quot;478&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
填寫基本資料，我沒請沒加密先生出場。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEioCwufvhW9hclyq5Vy6OKp0ABBKVKt5WacCskonZDlAOv1JLdgA0Gz_JDLJXaU1doGJjmJUxoc6-Wafgm1rw0cYl5ufuwNJ2CsmRF8sRd3DwayRNs8EzuHV4efulWnIJyUunNn6LrFsAo/s1600/net-chinese_03.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEioCwufvhW9hclyq5Vy6OKp0ABBKVKt5WacCskonZDlAOv1JLdgA0Gz_JDLJXaU1doGJjmJUxoc6-Wafgm1rw0cYl5ufuwNJ2CsmRF8sRd3DwayRNs8EzuHV4efulWnIJyUunNn6LrFsAo/s1600/net-chinese_03.png&quot; height=&quot;478&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
確認設定密碼，在這邊我們設定「plainpass」。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiXO_Qp06-5LEqgA9PsAKKKQ04s72zNG-Xfbp1oUJZSvmOJ_5mTvQ_JtTjplSG168eYdXf5D2nI3QRGOJn4VLJlrPYoCGyRBFNc2kb1mVrMJ7MYur8WyqK1z7U_TSkoP97TLNEq3-fa1Ps/s1600/net-chinese_04.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiXO_Qp06-5LEqgA9PsAKKKQ04s72zNG-Xfbp1oUJZSvmOJ_5mTvQ_JtTjplSG168eYdXf5D2nI3QRGOJn4VLJlrPYoCGyRBFNc2kb1mVrMJ7MYur8WyqK1z7U_TSkoP97TLNEq3-fa1Ps/s1600/net-chinese_04.png&quot; height=&quot;478&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
註冊信發出！&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi_JpXaBz4LAVmv8TzEjn2IMPMdDXmJBhBpm20YndXONUe3_0Vaw54-hd1hdb0frm60gDa4ll9Qs1416JuD85StjMIRhkzNTD4F9BlZm2SOL0SkIikpeHqhxxb32bW-adSjZlaZIfb38eA/s1600/net-chinese_05.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi_JpXaBz4LAVmv8TzEjn2IMPMdDXmJBhBpm20YndXONUe3_0Vaw54-hd1hdb0frm60gDa4ll9Qs1416JuD85StjMIRhkzNTD4F9BlZm2SOL0SkIikpeHqhxxb32bW-adSjZlaZIfb38eA/s1600/net-chinese_05.png&quot; height=&quot;478&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
到信箱點選註冊信。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi8Dum5e-I8Rjg0qwQysr70ISmo0kv6v2lI9O-3agigcfxTBMMbgVbWjOoLqYZFNTeAMSN5GQPCezBHCyODwbSEk7IfKqUPM959qRv-4_-nViFuVHwIG9hr1q8uKIaUi3wrcSozze20tiA/s1600/net-chinese_06.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi8Dum5e-I8Rjg0qwQysr70ISmo0kv6v2lI9O-3agigcfxTBMMbgVbWjOoLqYZFNTeAMSN5GQPCezBHCyODwbSEk7IfKqUPM959qRv-4_-nViFuVHwIG9hr1q8uKIaUi3wrcSozze20tiA/s1600/net-chinese_06.png&quot; height=&quot;442&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
再次輸入帳號密碼。&lt;br /&gt;
&lt;br /&gt;
這個頁面非常簡單，只有一個 form 而已，一開始我還以為是釣魚網站...&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgSQH_4N1Jg5NskEnYlG_2c6o6e-kcRY-XqkiByywovfzumPVm8OsIGbM4VkPS5e0SRlwcNPFhAbMousbT87sHK03diqK1mJGISElZK6XM5ixGIu7BAXWAfcJxNP0TL-LuUoofXEDM2vMQ/s1600/net-chinese_07.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgSQH_4N1Jg5NskEnYlG_2c6o6e-kcRY-XqkiByywovfzumPVm8OsIGbM4VkPS5e0SRlwcNPFhAbMousbT87sHK03diqK1mJGISElZK6XM5ixGIu7BAXWAfcJxNP0TL-LuUoofXEDM2vMQ/s1600/net-chinese_07.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
註冊成功了之後，我們來測試一下「忘記密碼」的功能。&lt;br /&gt;
&lt;br /&gt;
只要輸入身分證字號、管理信箱，就可以查詢原本的密碼。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgItxJPX0h8a8FhwbBuYIrbCeSBsyWEXd6TlqS8gImXiKn0prbF-ZIxGrlq2zeALmnRLths4bRbFIcbhDtNSlvlt8tRln9HRCPY6yMjCjo9h0Zc4rLOiayJQFQj8eoMYFpc1Ywtlcf0bGg/s1600/net-chinese_08.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgItxJPX0h8a8FhwbBuYIrbCeSBsyWEXd6TlqS8gImXiKn0prbF-ZIxGrlq2zeALmnRLths4bRbFIcbhDtNSlvlt8tRln9HRCPY6yMjCjo9h0Zc4rLOiayJQFQj8eoMYFpc1Ywtlcf0bGg/s1600/net-chinese_08.png&quot; height=&quot;478&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
「密碼函已寄到您的管理信箱!!」&lt;br /&gt;
&lt;br /&gt;
聽起來答案已經揭曉了。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgXnsmwSMSb_2LHrV8IWzK4aWezjk-37y-kS8Qvda8CNDL1qpyb47ISJuVWq0grE6FDQDCXIqloizNyTN78vckA0NNiBWg7f0Rrdnex5zSnovHOMIjLHNSlX7PeeydRBlC2vmFhsUPEHx8/s1600/net-chinese_09.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgXnsmwSMSb_2LHrV8IWzK4aWezjk-37y-kS8Qvda8CNDL1qpyb47ISJuVWq0grE6FDQDCXIqloizNyTN78vckA0NNiBWg7f0Rrdnex5zSnovHOMIjLHNSlX7PeeydRBlC2vmFhsUPEHx8/s1600/net-chinese_09.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
在信箱中果然收到了密碼函：「您的管理人密碼如下，密碼：plainpass」&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi0HcNHcbTcR4npVbvGqoyFevZg9u4XmSvcmrY4X_F70fbpL9YONfqnh1GKbEz6Jw2MwssymYYf7egs6dzjLcY08LVQk_oNRXlTocKz0nOQ4yl6UBFfDXEa0OIpdcOJnuRvuFPeGbnNmI8/s1600/net-chinese_10.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi0HcNHcbTcR4npVbvGqoyFevZg9u4XmSvcmrY4X_F70fbpL9YONfqnh1GKbEz6Jw2MwssymYYf7egs6dzjLcY08LVQk_oNRXlTocKz0nOQ4yl6UBFfDXEa0OIpdcOJnuRvuFPeGbnNmI8/s1600/net-chinese_10.png&quot; height=&quot;472&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
DNS 第四篇，我們對 DNS 服務的密碼機制越來越感到茫然。&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;「網路中文」密碼沒加密！&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
日期：2014-01-22&lt;br /&gt;
名稱：網路中文&lt;br /&gt;
網址：&lt;a href=&quot;http://www.net-chinese.com.tw/&quot;&gt;http://www.net-chinese.com.tw/&lt;/a&gt;&lt;br /&gt;
結果：密碼沒加密
&lt;br /&gt;
&lt;br /&gt;
感謝 Richer Yang 的爆料！</content><link rel='replies' type='application/atom+xml' href='http://plainpass.com/feeds/4898635860241044179/comments/default' title='張貼留言'/><link rel='replies' type='text/html' href='http://plainpass.com/2014/01/net-chinese-stores-passwords-in-plaintext.html#comment-form' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/4898635860241044179'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/4898635860241044179'/><link rel='alternate' type='text/html' href='http://plainpass.com/2014/01/net-chinese-stores-passwords-in-plaintext.html' title='「網路中文」密碼沒加密！'/><author><name>Allen Own</name><uri>http://www.blogger.com/profile/07432128723498860159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgOTtJR54trZACfSZ1S-GfX8dHsYH3aLjRW6yUlr-mhSJ5cHFa2f0iPvaOYEB_AGShQpwl0tFbllzbdVooCPAh2wXx0OaEUOP6mdEB5n-yOUmnDwJC4LQ2gHlp7I4Z4Lk/s220/A2.png'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhMvfz-R-OJXabMmyxHlNj-purdd4FuQBd8qwnEuQHZMKcO2zX0cIM0ZLMruHx1SFtDbA37GayC5h4F9MfbsLU8JvGY0LwmihjqDW9wR17ZcDo_F7k2jZCmxItbNJLXz7wafrK8aV1DUf4/s72-c/net-chinese_01.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4521309719030850665.post-5715223287800778170</id><published>2014-01-22T23:59:00.000+08:00</published><updated>2014-01-22T23:59:29.305+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Forward"/><category scheme="http://www.blogger.com/atom/ns#" term="PlainPass"/><category scheme="http://www.blogger.com/atom/ns#" term="Taiwan"/><title type='text'>[轉載] 3D驗證密碼....這麼好取得? creditcard/批踢踢實業坊</title><content type='html'>感謝網友轉貼此文，內容的真實性就請大家自己判斷囉！&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://www.ptt.cc/bbs/creditcard/M.1367419439.A.519.html&quot; target=&quot;_blank&quot;&gt;http://www.ptt.cc/bbs/creditcard/M.1367419439.A.519.html&lt;/a&gt;&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgW-pBkq6foA7pukIntHIgwo98svDiGSvbX53hBnCbDkhHAh4-jEUJx3M-SfK7_ruZBbZ9rLms0_YG02LAWtI_Pup_YIvkplOBPFtPTpHk-4xfiW2Iol-5VJiSbI0BN8BffP-Xoch0zOAA/s1600/%5B%E9%96%92%E8%81%8A%5D+3D%E9%A9%97%E8%AD%89%E5%AF%86%E7%A2%BC....%E9%80%99%E9%BA%BC%E5%A5%BD%E5%8F%96%E5%BE%97%3f+-+%E7%9C%8B%E6%9D%BF+creditcard+-+%E6%89%B9%E8%B8%A2%E8%B8%A2%E5%AF%A6%E6%A5%AD%E5%9D%8A.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgW-pBkq6foA7pukIntHIgwo98svDiGSvbX53hBnCbDkhHAh4-jEUJx3M-SfK7_ruZBbZ9rLms0_YG02LAWtI_Pup_YIvkplOBPFtPTpHk-4xfiW2Iol-5VJiSbI0BN8BffP-Xoch0zOAA/s1600/%5B%E9%96%92%E8%81%8A%5D+3D%E9%A9%97%E8%AD%89%E5%AF%86%E7%A2%BC....%E9%80%99%E9%BA%BC%E5%A5%BD%E5%8F%96%E5%BE%97%3f+-+%E7%9C%8B%E6%9D%BF+creditcard+-+%E6%89%B9%E8%B8%A2%E8%B8%A2%E5%AF%A6%E6%A5%AD%E5%9D%8A.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;</content><link rel='replies' type='application/atom+xml' href='http://plainpass.com/feeds/5715223287800778170/comments/default' title='張貼留言'/><link rel='replies' type='text/html' href='http://plainpass.com/2014/01/bank-3d-secure-plaintext.html#comment-form' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/5715223287800778170'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/5715223287800778170'/><link rel='alternate' type='text/html' href='http://plainpass.com/2014/01/bank-3d-secure-plaintext.html' title='[轉載] 3D驗證密碼....這麼好取得? creditcard/批踢踢實業坊'/><author><name>Allen Own</name><uri>http://www.blogger.com/profile/07432128723498860159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgOTtJR54trZACfSZ1S-GfX8dHsYH3aLjRW6yUlr-mhSJ5cHFa2f0iPvaOYEB_AGShQpwl0tFbllzbdVooCPAh2wXx0OaEUOP6mdEB5n-yOUmnDwJC4LQ2gHlp7I4Z4Lk/s220/A2.png'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgW-pBkq6foA7pukIntHIgwo98svDiGSvbX53hBnCbDkhHAh4-jEUJx3M-SfK7_ruZBbZ9rLms0_YG02LAWtI_Pup_YIvkplOBPFtPTpHk-4xfiW2Iol-5VJiSbI0BN8BffP-Xoch0zOAA/s1600/%5B%E9%96%92%E8%81%8A%5D+3D%E9%A9%97%E8%AD%89%E5%AF%86%E7%A2%BC....%E9%80%99%E9%BA%BC%E5%A5%BD%E5%8F%96%E5%BE%97%3f+-+%E7%9C%8B%E6%9D%BF+creditcard+-+%E6%89%B9%E8%B8%A2%E8%B8%A2%E5%AF%A6%E6%A5%AD%E5%9D%8A.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4521309719030850665.post-1137549058636710856</id><published>2014-01-13T21:50:00.000+08:00</published><updated>2014-01-13T21:55:51.416+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="DNS"/><category scheme="http://www.blogger.com/atom/ns#" term="PlainPass"/><category scheme="http://www.blogger.com/atom/ns#" term="Taiwan"/><title type='text'>「TISNet 大同網際網路」密碼沒加密！</title><content type='html'>我的密碼沒加密 DNS 系列第三篇，讓我們來看看「&lt;a href=&quot;http://reg.tisnet.net.tw/&quot; target=&quot;_blank&quot;&gt;TISNet 大同網際網路&lt;/a&gt;」。TISNet 是協志聯合科技在 1996 由大同公司轉投資成立。網站上除了網域名稱之外，還提供了虛擬主機、郵件等整合服務。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg5ZQA3jNshJDFWuevEOoFodnuh5BqJbnOTuPQXJCpwFUV-La5rKJDSREPFpcEH5VKG4SEtk7sAgY8OKhjpwx9u1fxTDlYrOizHOBYGm15HMQ1XihpBR_zSxX_I5H9ojGtYrXcGfnQlMFA/s1600/tisnet_01.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg5ZQA3jNshJDFWuevEOoFodnuh5BqJbnOTuPQXJCpwFUV-La5rKJDSREPFpcEH5VKG4SEtk7sAgY8OKhjpwx9u1fxTDlYrOizHOBYGm15HMQ1XihpBR_zSxX_I5H9ojGtYrXcGfnQlMFA/s1600/tisnet_01.png&quot; height=&quot;482&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
先讓我們來看看網站上有關安全的描述，似乎都只有提到請「會員」善加保管密碼，「協志」該如何負責沒有提到。&lt;br /&gt;
&lt;blockquote class=&quot;tr_bq&quot;&gt;
（四）會員同意妥善保管個人之帳號及密碼，並不得與他人共用；會員並應不定期更新自己密碼，並於使用完服務後確實將帳號作登出動作，以免帳號被他人惡意盜用。&amp;nbsp;&lt;/blockquote&gt;
&lt;div&gt;
&lt;blockquote class=&quot;tr_bq&quot;&gt;
會員有義務妥善保管在協志科技之帳號與密碼，並為此組帳號與密碼登入系統後所進行之一切活動負責。為維護會員自身權益，請勿將帳號與密碼洩露或提供予第三人知悉，或出借或轉讓他人使用。若會員發現帳號或密碼遭人非法使用或有任何異常破壞使用安全之情形時，應立即通知協志聯合科技股份有限公司。但若是因為您的保管疏忽，而導致帳號、密碼遭他人非法使用時，協志科技將不負責處理。&amp;nbsp;&lt;/blockquote&gt;
&lt;/div&gt;
那就讓我們來看看會員的密碼有沒有加密吧。&lt;br /&gt;
先讓我們註冊一組帳號，為什麼這些網域名稱申請的網站都喜歡用身分證字號來當帳號呢？&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgLS0ztN-4Dz5hC4s0oVjiMoQZShJtskGGrBLdQC6eDWHAJcmacIwLrIgFSNg-79smCqvKZkoQtVmqfE6aclteTrYbOGrAhSCVGXwgh9trCMhaftY3-lFy0h9wTi9hZTS_NJ7PdXr_rhqQ/s1600/tisnet_02.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgLS0ztN-4Dz5hC4s0oVjiMoQZShJtskGGrBLdQC6eDWHAJcmacIwLrIgFSNg-79smCqvKZkoQtVmqfE6aclteTrYbOGrAhSCVGXwgh9trCMhaftY3-lFy0h9wTi9hZTS_NJ7PdXr_rhqQ/s1600/tisnet_02.png&quot; height=&quot;482&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
詳細的填寫所有個人資料。&lt;br /&gt;
（希望這次 PlainPass 不要再被擋掉了...）&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi1UaaSjk6JTSD3mOLl4E-Jntf4AYmy9PFiIWBxzvOh-oeURJxPJ1nEhoGTfC1GYEcgrJU96nJCA2Sz3Ak-y6I1VKEBN0AlCkf35niqH4pYt8kDzit59WGAFG93Vz9a24nP95prspsFU2I/s1600/tisnet_03.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi1UaaSjk6JTSD3mOLl4E-Jntf4AYmy9PFiIWBxzvOh-oeURJxPJ1nEhoGTfC1GYEcgrJU96nJCA2Sz3Ak-y6I1VKEBN0AlCkf35niqH4pYt8kDzit59WGAFG93Vz9a24nP95prspsFU2I/s1600/tisnet_03.png&quot; height=&quot;482&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
帳號註冊完畢之後，我們接著來看看「會員資料修改」。&lt;br /&gt;
赫然發現畫面上大大的四個字「登入密碼」，而且有星號保護。&lt;br /&gt;
&lt;br /&gt;
「各位同學，有星號，代表有加密，對不對？」『零分！』&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiOdSNDATTr3zmaa6NU0BJk-GUPrJe9bezDN80d71OQRwG12WBTlVg1MVlCRVfyMNZqcNT4jVisLm2-XnBErq3ILjRFKbGLxl7sItOndfXnea-hHG8ERl2wrKCvHkzYPAJC4VzT4LrFVlE/s1600/tisnet_04.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiOdSNDATTr3zmaa6NU0BJk-GUPrJe9bezDN80d71OQRwG12WBTlVg1MVlCRVfyMNZqcNT4jVisLm2-XnBErq3ILjRFKbGLxl7sItOndfXnea-hHG8ERl2wrKCvHkzYPAJC4VzT4LrFVlE/s1600/tisnet_04.png&quot; height=&quot;482&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
讓我們檢視原始碼，或者是把 input 屬性的「password」拿掉，就會現出原形了。&lt;br /&gt;
連查詢密碼的功能都不用，直接修改個人資料就可以看到原始的密碼了。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhwaJjWX23WI9SPrUpKAO6IZzmg9wIXjWtcW1sqlXcfDXojs2Pbm7QZi02p6qyNyLK2v4Tpo6dlhN2l_yCNYEacULMKHDY7F9VIgTvBulbM0eqUOHohNnCueLJtF_ETATC-lsEOgUhPTtI/s1600/tisnet_05.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhwaJjWX23WI9SPrUpKAO6IZzmg9wIXjWtcW1sqlXcfDXojs2Pbm7QZi02p6qyNyLK2v4Tpo6dlhN2l_yCNYEacULMKHDY7F9VIgTvBulbM0eqUOHohNnCueLJtF_ETATC-lsEOgUhPTtI/s1600/tisnet_05.png&quot; height=&quot;482&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
當然我們秉持的一貫的原則，還是要來測試一下密碼查詢功能。&lt;br /&gt;
&lt;br /&gt;
輸入我們的身分證字號即可查詢密碼：「我們會將密碼，寄回您原先的預設信箱！！」&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgPBvQD6qEX73-rg9y6c8N9PmyJpODDkOiOisvwxbhf5YxhJMY_biGPybnGASlgWkhUd7c5BMPwequA7_y43yv5_2BLGzLGrEomS9iqtCZDAKO1UPWL57W5GfhyphenhyphenjID2NCraWT-2f_-CNn4/s1600/tisnet_06.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgPBvQD6qEX73-rg9y6c8N9PmyJpODDkOiOisvwxbhf5YxhJMY_biGPybnGASlgWkhUd7c5BMPwequA7_y43yv5_2BLGzLGrEomS9iqtCZDAKO1UPWL57W5GfhyphenhyphenjID2NCraWT-2f_-CNn4/s1600/tisnet_06.png&quot; height=&quot;482&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
密碼已寄出！&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgLQ8eZcXOT9zDYxKGT6XJzS2vWD4skG0Vi8ocikTFbLp-GVjTJqv4578wGwOvs6cuQ0-MVPshl8KZxXRO4VgKjhhq67UdrYyCD6LBIwSotuEo7L9UAWc5j40j-7IXcW1FirSpxz4WKcbM/s1600/tisnet_07.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgLQ8eZcXOT9zDYxKGT6XJzS2vWD4skG0Vi8ocikTFbLp-GVjTJqv4578wGwOvs6cuQ0-MVPshl8KZxXRO4VgKjhhq67UdrYyCD6LBIwSotuEo7L9UAWc5j40j-7IXcW1FirSpxz4WKcbM/s1600/tisnet_07.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div&gt;
不過我們遲遲等不到信件寄過來，希望不會又是另一家把「plainpass」帳號信件另外處理的網站。:P&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;「TISNet 大同網際網路 域名註冊」密碼沒加密！&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;br /&gt;
日期：2014-01-11&lt;br /&gt;
名稱：TISNet大同網際網路-域名註冊&lt;br /&gt;
網址：&lt;a href=&quot;http://reg.tisnet.net.tw/&quot;&gt;http://reg.tisnet.net.tw&lt;/a&gt;&lt;br /&gt;
結果：密碼沒加密
&lt;br /&gt;
&lt;br /&gt;
感謝 凍仁翔 及 pptpb.tw 的爆料！</content><link rel='replies' type='application/atom+xml' href='http://plainpass.com/feeds/1137549058636710856/comments/default' title='張貼留言'/><link rel='replies' type='text/html' href='http://plainpass.com/2014/01/tisnet-stores-passwords-in-plaintext.html#comment-form' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/1137549058636710856'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/1137549058636710856'/><link rel='alternate' type='text/html' href='http://plainpass.com/2014/01/tisnet-stores-passwords-in-plaintext.html' title='「TISNet 大同網際網路」密碼沒加密！'/><author><name>Allen Own</name><uri>http://www.blogger.com/profile/07432128723498860159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgOTtJR54trZACfSZ1S-GfX8dHsYH3aLjRW6yUlr-mhSJ5cHFa2f0iPvaOYEB_AGShQpwl0tFbllzbdVooCPAh2wXx0OaEUOP6mdEB5n-yOUmnDwJC4LQ2gHlp7I4Z4Lk/s220/A2.png'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg5ZQA3jNshJDFWuevEOoFodnuh5BqJbnOTuPQXJCpwFUV-La5rKJDSREPFpcEH5VKG4SEtk7sAgY8OKhjpwx9u1fxTDlYrOizHOBYGm15HMQ1XihpBR_zSxX_I5H9ojGtYrXcGfnQlMFA/s72-c/tisnet_01.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4521309719030850665.post-7084148098670698756</id><published>2014-01-07T19:40:00.000+08:00</published><updated>2014-01-07T19:40:27.646+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="DNS"/><category scheme="http://www.blogger.com/atom/ns#" term="PlainPass"/><category scheme="http://www.blogger.com/atom/ns#" term="Taiwan"/><title type='text'>「遠傳 Seednet 網域名稱申請」密碼沒加密！</title><content type='html'>DNS 系列的第二篇，我們來看看「&lt;a href=&quot;http://rs.seed.net.tw/&quot; target=&quot;_blank&quot;&gt;遠傳 Seednet 網域名稱申請&lt;/a&gt;」。&lt;br /&gt;
&lt;br /&gt;
Seednet 是國內非常老牌的 ISP，對於網路發展的貢獻良多。&lt;br /&gt;
但是往往「年長」的系統，都會有一些「年長」的設計，就讓我們來看看密碼吧。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh2lCzaPEhrcGOUT9Rdf-u45qE8NL73FdN1SqgLsSyrDft3XiNEnPc9RAuLjXMCYQAhrRkleEOKGeyJl2Bh3kMZgpbxgnKNudchlZtzHkPGlZQPfVlPxou9WiqncrYHpB0PBRtTM9Cu9Xk/s1600/seednet_dn_01.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh2lCzaPEhrcGOUT9Rdf-u45qE8NL73FdN1SqgLsSyrDft3XiNEnPc9RAuLjXMCYQAhrRkleEOKGeyJl2Bh3kMZgpbxgnKNudchlZtzHkPGlZQPfVlPxou9WiqncrYHpB0PBRtTM9Cu9Xk/s1600/seednet_dn_01.png&quot; height=&quot;482&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
首先要有一個帳號，就必須要直接註冊一個域名。&lt;br /&gt;
如果花點錢可以知道密碼有沒有加密，也是值得啦。&lt;br /&gt;
就讓我們按下「立即申請」吧。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi_D-6Dt7w5lq9ZWIAzCRzR6Jk_gtmwaaDV68y-UNPYza4TGllLN13VRkqmOjB_zTZ4F0IgpzdZqagyk3H4K4U5Hud7QoZWyXkZwDwtQHN8i0txamyq2DCDF0wpzn2aaH_TJRxhdh8-lh0/s1600/seednet_dn_02.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi_D-6Dt7w5lq9ZWIAzCRzR6Jk_gtmwaaDV68y-UNPYza4TGllLN13VRkqmOjB_zTZ4F0IgpzdZqagyk3H4K4U5Hud7QoZWyXkZwDwtQHN8i0txamyq2DCDF0wpzn2aaH_TJRxhdh8-lh0/s1600/seednet_dn_02.png&quot; height=&quot;482&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
要申請什麼域名好呢？那就來個「plainpass.tw」吧！並且也遵循個人資料保護法喔！&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiZE1wwuUY0qAb5_7DzBY9hG6_u2RWn6gyFa5qmtl2WgUdp3lX7rP31_Ez7P9myAGnl12wK_p0q0iZkAMmwNsYmSawxSFqLVOMtANcypWF0vKlwzgySi7Ag3fFGyKjdkf1wKpscms5QJbA/s1600/seednet_dn_03.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiZE1wwuUY0qAb5_7DzBY9hG6_u2RWn6gyFa5qmtl2WgUdp3lX7rP31_Ez7P9myAGnl12wK_p0q0iZkAMmwNsYmSawxSFqLVOMtANcypWF0vKlwzgySi7Ag3fFGyKjdkf1wKpscms5QJbA/s1600/seednet_dn_03.png&quot; height=&quot;482&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
同意條款。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhJWAclAtXztVF1T79W9aXi1MuUPxL_nHwBHn0yKK-2yT-eXasFGV222d4F8BmLaSSsOGziUUOGJtZ0_j0zY1L31CZNCTR6BP7dNZtflymWgZJLjLLkVIdM6BIRJp1hLl82UQzqbNvtl3w/s1600/seednet_dn_04.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhJWAclAtXztVF1T79W9aXi1MuUPxL_nHwBHn0yKK-2yT-eXasFGV222d4F8BmLaSSsOGziUUOGJtZ0_j0zY1L31CZNCTR6BP7dNZtflymWgZJLjLLkVIdM6BIRJp1hLl82UQzqbNvtl3w/s1600/seednet_dn_04.png&quot; height=&quot;482&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
接著是要輸入身分證字號，來開立新帳號，第一次密碼則不用輸入。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgmKmSF3EjkMlv4WpvLrBcWf1zfptRURdCqWCvkRz5BFc1S0YmRUs6cwQGXX1gmdZrnThc8rdTGyvoaN9GWPlZoHnZ7Lz_B9_YxfXaX6TmRjgv47pNeIzA-TCL1e7wLyzwXZ2B1gjQba_Y/s1600/seednet_dn_05.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgmKmSF3EjkMlv4WpvLrBcWf1zfptRURdCqWCvkRz5BFc1S0YmRUs6cwQGXX1gmdZrnThc8rdTGyvoaN9GWPlZoHnZ7Lz_B9_YxfXaX6TmRjgv47pNeIzA-TCL1e7wLyzwXZ2B1gjQba_Y/s1600/seednet_dn_05.png&quot; height=&quot;482&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
填寫基本資料，包括密碼。&lt;br /&gt;
密碼當然不能亂填啊，要好好想一個好密碼。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiujACVkt1Lam37D2PrU_ajx_zVaFTS6EVxBQCBgjBGA41nVsTGCFMiLhFIyF80PhSk_-6eo_Y59FbE4oyczQwVJmB5Jj_l3ov0GxTDL9d7DL1FWwGq1Lw4UTKKNEeJ34NsG7g-b_sxFmw/s1600/seednet_dn_06.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiujACVkt1Lam37D2PrU_ajx_zVaFTS6EVxBQCBgjBGA41nVsTGCFMiLhFIyF80PhSk_-6eo_Y59FbE4oyczQwVJmB5Jj_l3ov0GxTDL9d7DL1FWwGq1Lw4UTKKNEeJ34NsG7g-b_sxFmw/s1600/seednet_dn_06.png&quot; height=&quot;482&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
什麼？密碼竟然只能八個字元？&lt;br /&gt;
果然是以前的系統會有的設計。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEijYDLntb57WW-x7ikqnAg_fC5snOHjnrxXZrCDRbfi27pzswjyiJMc-FO-K2r9w2wtFLad1rPYAI35Uof4gbSOhlCJSafpGh9f2eR8FrSQ3yycR4oHxbZbKOtUnCEL5yvurYqKIxOzDng/s1600/seednet_dn_07.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEijYDLntb57WW-x7ikqnAg_fC5snOHjnrxXZrCDRbfi27pzswjyiJMc-FO-K2r9w2wtFLad1rPYAI35Uof4gbSOhlCJSafpGh9f2eR8FrSQ3yycR4oHxbZbKOtUnCEL5yvurYqKIxOzDng/s1600/seednet_dn_07.png&quot; height=&quot;482&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
終於申請完畢之後，帳號也開通了。&lt;br /&gt;
域名會經過審核付款後才生效。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEijOhVhNqx3vfA8OWjHG3qK3X76QK5cqR0yzbxrgLY0Rl9TBhDS2usKAUHOcqx88hchKRYqpFkzOYyLQt-4Y51zV0n10VJ_zdmvYuDCd7BwlrT5kNZYFr91Fchfm7cbrotlQBtCifTCH_A/s1600/seednet_dn_08.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEijOhVhNqx3vfA8OWjHG3qK3X76QK5cqR0yzbxrgLY0Rl9TBhDS2usKAUHOcqx88hchKRYqpFkzOYyLQt-4Y51zV0n10VJ_zdmvYuDCd7BwlrT5kNZYFr91Fchfm7cbrotlQBtCifTCH_A/s1600/seednet_dn_08.png&quot; height=&quot;482&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
接著回到首頁「我的域名管理」這邊。&lt;br /&gt;
會看到我們域名的狀況、跟個人資料修改部分。&lt;br /&gt;
&lt;br /&gt;
在這邊看到「用戶密碼」，是修改密碼的功能，讓我們進去看看。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiM9iMJ9tJNBLXph6XE1GViwrVWlFHyCelGo75OB7NPw321RxIxSmjUPZRnZLV_Irf1FrIQCFkfTao6s0jRKguD3XcLf3f_foB6cyymtEpgIl65igp7VHwC9IHin0vmwdERfEX74kKxeog/s1600/seednet_dn_09.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiM9iMJ9tJNBLXph6XE1GViwrVWlFHyCelGo75OB7NPw321RxIxSmjUPZRnZLV_Irf1FrIQCFkfTao6s0jRKguD3XcLf3f_foB6cyymtEpgIl65igp7VHwC9IHin0vmwdERfEX74kKxeog/s1600/seednet_dn_09.png&quot; height=&quot;482&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
什麼！&lt;br /&gt;
密碼就這樣直接秀出來了...&lt;br /&gt;
實在是令人吃驚...&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjPb9VJRy11scmWCmOp1MpcZPDhhJPwx45JXgO3-KfSy3TePpYueqJSLCT_MI4qLQN64vog9T-hYPv2N9FN-3UGweeGHHlLbiEJNCmWiPbjeDatl2Y1dWy4xTaugWSmTbsa9roodBkcdl8/s1600/seednet_dn_10.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjPb9VJRy11scmWCmOp1MpcZPDhhJPwx45JXgO3-KfSy3TePpYueqJSLCT_MI4qLQN64vog9T-hYPv2N9FN-3UGweeGHHlLbiEJNCmWiPbjeDatl2Y1dWy4xTaugWSmTbsa9roodBkcdl8/s1600/seednet_dn_10.png&quot; height=&quot;482&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
當然，我們也可以直接用查詢密碼的功能，系統也會乖乖的把密碼寄給我們。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEizzbVFEWUGI6XHHkss8LIqpmuuiJtTioL8d6KD85bZps230TJ5_XdDsvB38geWl8xIJ2T5vXiTV-bzch6V2Q4fv1MEK0OUmqtU0lT6WboBdy_mAQ4wVxwFWEsJuDzToVfeNScG4w_lMqY/s1600/seednet_dn_11.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEizzbVFEWUGI6XHHkss8LIqpmuuiJtTioL8d6KD85bZps230TJ5_XdDsvB38geWl8xIJ2T5vXiTV-bzch6V2Q4fv1MEK0OUmqtU0lT6WboBdy_mAQ4wVxwFWEsJuDzToVfeNScG4w_lMqY/s1600/seednet_dn_11.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
因此我們要很遺憾的說，Seednet 也沒有通過我們的測試。&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;
&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;「遠傳 Seednet 網域名稱申請」密碼沒加密！&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
日期：2014-01-07&lt;br /&gt;
名稱：遠傳 Seednet 網域名稱申請&lt;br /&gt;
網址：&lt;a href=&quot;http://rs.seed.net.tw/&quot;&gt;http://rs.seed.net.tw/&lt;/a&gt;&lt;br /&gt;
結果：密碼沒加密
&lt;br /&gt;
&lt;br /&gt;
感謝 linpc 的爆料！</content><link rel='replies' type='application/atom+xml' href='http://plainpass.com/feeds/7084148098670698756/comments/default' title='張貼留言'/><link rel='replies' type='text/html' href='http://plainpass.com/2014/01/seednet-domain-stores-passwords-in-plaintext.html#comment-form' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/7084148098670698756'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/7084148098670698756'/><link rel='alternate' type='text/html' href='http://plainpass.com/2014/01/seednet-domain-stores-passwords-in-plaintext.html' title='「遠傳 Seednet 網域名稱申請」密碼沒加密！'/><author><name>Allen Own</name><uri>http://www.blogger.com/profile/07432128723498860159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgOTtJR54trZACfSZ1S-GfX8dHsYH3aLjRW6yUlr-mhSJ5cHFa2f0iPvaOYEB_AGShQpwl0tFbllzbdVooCPAh2wXx0OaEUOP6mdEB5n-yOUmnDwJC4LQ2gHlp7I4Z4Lk/s220/A2.png'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh2lCzaPEhrcGOUT9Rdf-u45qE8NL73FdN1SqgLsSyrDft3XiNEnPc9RAuLjXMCYQAhrRkleEOKGeyJl2Bh3kMZgpbxgnKNudchlZtzHkPGlZQPfVlPxou9WiqncrYHpB0PBRtTM9Cu9Xk/s72-c/seednet_dn_01.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4521309719030850665.post-7180761039319723880</id><published>2014-01-06T16:54:00.001+08:00</published><updated>2014-01-06T16:54:21.525+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="DNS"/><category scheme="http://www.blogger.com/atom/ns#" term="PlainPass"/><category scheme="http://www.blogger.com/atom/ns#" term="Taiwan"/><title type='text'>「PChome Online 網路家庭-買網址」密碼沒加密！</title><content type='html'>「&lt;a href=&quot;http://myname.pchome.com.tw/&quot; target=&quot;_blank&quot;&gt;PChome Online 網路家庭-買網址&lt;/a&gt;」是很多人買網域名稱的選擇，價格便宜、介面友善。但是卻不斷有使用者來信通報：該網站的密碼似乎沒加密？&lt;br /&gt;
&lt;br /&gt;
身為電子商務龍頭，究竟密碼機制安不安全呢？就讓我們來看看吧！&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiUsNpqWfgHTXBSh3PD96WcDOEqKpSmZFR9fDFY0ZQZbpIH7Dqg02_-9qxo2sdW6QJfXR2KlCjTF7ttXtlFERk3puqOgkbqddPimhYiExO64ANVFrGoZUdE6ll3ZElrXTHcymziMNx2XsI/s1600/pchome_myname_01.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiUsNpqWfgHTXBSh3PD96WcDOEqKpSmZFR9fDFY0ZQZbpIH7Dqg02_-9qxo2sdW6QJfXR2KlCjTF7ttXtlFERk3puqOgkbqddPimhYiExO64ANVFrGoZUdE6ll3ZElrXTHcymziMNx2XsI/s1600/pchome_myname_01.png&quot; height=&quot;482&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
在「&lt;a href=&quot;http://faq.pchome.com.tw/faq_solution.html?q_id=16&amp;amp;c_nickname=member&amp;amp;f_id=4&quot; target=&quot;_blank&quot;&gt;隱私權聲明&lt;/a&gt;」 中寫著：&lt;br /&gt;
&lt;blockquote class=&quot;tr_bq&quot;&gt;
■ 資料安全 &lt;br /&gt;
&lt;br /&gt;
PChome 網路家庭將以合於產業標準之合理技術及程序，維護個人資料之安全。&lt;/blockquote&gt;
相當有彈性的一句話，實際背後的安全機制我們無從得知。&lt;br /&gt;
無論如何，讓我們來測試看看吧！&lt;br /&gt;
&lt;br /&gt;
首先註冊一個帳號：&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgO4Zbiy48nDvMiMQVkVkARVg3tLErFrTpOENmMOeHo9-dw5Sf1NZDsCFcalfhQJ0jx2ojdleSwF_uB3dF283q6mdw7Mt4ig9RP5wsy-p8aZVjwsGiqoOIBl232enws9AmlVRvMJqhfxXM/s1600/pchome_myname_02.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgO4Zbiy48nDvMiMQVkVkARVg3tLErFrTpOENmMOeHo9-dw5Sf1NZDsCFcalfhQJ0jx2ojdleSwF_uB3dF283q6mdw7Mt4ig9RP5wsy-p8aZVjwsGiqoOIBl232enws9AmlVRvMJqhfxXM/s1600/pchome_myname_02.png&quot; height=&quot;483&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
很快的帳號註冊完畢了！按下一步即為登入狀態。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjtGdq7sdxcm5nP1mbHZsT3d5Y34OXsXsRM9utXsXWBDyfUuFavmMqNkuA-iGIVSB0il3WnG_RGqL3i4soqw-V3_S-oXL5CGCi8Qsb2qSrzVlUwt5ggFq8ncoBsC1T95qktvpaDAZKFaaI/s1600/pchome_myname_03.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjtGdq7sdxcm5nP1mbHZsT3d5Y34OXsXsRM9utXsXWBDyfUuFavmMqNkuA-iGIVSB0il3WnG_RGqL3i4soqw-V3_S-oXL5CGCi8Qsb2qSrzVlUwt5ggFq8ncoBsC1T95qktvpaDAZKFaaI/s1600/pchome_myname_03.png&quot; height=&quot;482&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
點選右邊的「查詢密碼」。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEidqGdPJiBAXpNR46PZu8bHcISBhArmP6E-LfcrjJUDLeyiufFhi-qo7jMdYMLVLY-c8MLMistR3YlznWR7GoilrE3lvPQIdwXuN7db3WIT8lkSZJ_pkWija7lYAMUC5naCR24rOkLnlJ4/s1600/pchome_myname_04.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEidqGdPJiBAXpNR46PZu8bHcISBhArmP6E-LfcrjJUDLeyiufFhi-qo7jMdYMLVLY-c8MLMistR3YlznWR7GoilrE3lvPQIdwXuN7db3WIT8lkSZJ_pkWija7lYAMUC5naCR24rOkLnlJ4/s1600/pchome_myname_04.png&quot; height=&quot;482&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
網頁上清楚的寫著：「我們會立即將密碼寄到此E-mail！」&lt;br /&gt;
所以結局我們依稀已經看到了。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhzgxhyqRhJIfaA8OOeU7BD1HeqrLu4BMJpeJelaYj0gYcX5xv9g0brHCKxGaj7t2vuw6DLPX6cCMZ32DoIe61VJMbW13eecXh8b8_G_17nsKluuH5rr5k77Yj3Wy3s7_rmusMnmXK92I0/s1600/pchome_myname_05.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhzgxhyqRhJIfaA8OOeU7BD1HeqrLu4BMJpeJelaYj0gYcX5xv9g0brHCKxGaj7t2vuw6DLPX6cCMZ32DoIe61VJMbW13eecXh8b8_G_17nsKluuH5rr5k77Yj3Wy3s7_rmusMnmXK92I0/s1600/pchome_myname_05.png&quot; height=&quot;482&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
「已發出密碼通知信」，讓我們趕快去收個信吧。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEja_71yP60mo2S76mMLxX_ppWlwSHCH01JQv9OtD0VJpUJ9WN668AGGxbX-fFoxjFwxD9BcI5aPgCK3RW5GMIRnn30fEZvVav8jjFqGd45CsRVJcOfHHNFNAMMPV2ki3WE032TVYcNisHU/s1600/pchome_myname_06.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEja_71yP60mo2S76mMLxX_ppWlwSHCH01JQv9OtD0VJpUJ9WN668AGGxbX-fFoxjFwxD9BcI5aPgCK3RW5GMIRnn30fEZvVav8jjFqGd45CsRVJcOfHHNFNAMMPV2ki3WE032TVYcNisHU/s1600/pchome_myname_06.png&quot; height=&quot;482&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
在信中我們清楚的看到我們的密碼「plainpass」&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEioyQqx0e0DVrRxV34d6j_SMg0mHYT0cqaHVKz4HeSSKLB_Xt280phL7muvWBaIuzDO39HIE-Jl4u5xouSoHJx_KsXfDErrVD1samgXF5bLsi4kMFodyXNrqMaRQCcemlZ5tv3OBtOXogw/s1600/pchome_myname_07.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEioyQqx0e0DVrRxV34d6j_SMg0mHYT0cqaHVKz4HeSSKLB_Xt280phL7muvWBaIuzDO39HIE-Jl4u5xouSoHJx_KsXfDErrVD1samgXF5bLsi4kMFodyXNrqMaRQCcemlZ5tv3OBtOXogw/s1600/pchome_myname_07.png&quot; height=&quot;526&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;「PChome Online 網路家庭-買網址」密碼沒加密！&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
PChome 已經是累犯了喔，如果可以的話請趕快改進架構跟機制吧！&lt;br /&gt;
&lt;br /&gt;
日期：2014-01-05&lt;br /&gt;
名稱：PChome Online 網路家庭-買網址&lt;br /&gt;
網址：&lt;a href=&quot;http://myname.pchome.com.tw/&quot;&gt;http://myname.pchome.com.tw&lt;/a&gt;&lt;br /&gt;
結果：密碼沒加密
&lt;br /&gt;
&lt;br /&gt;
感謝 Anonymous、Anonymous 以及 Anonymous 的爆料！</content><link rel='replies' type='application/atom+xml' href='http://plainpass.com/feeds/7180761039319723880/comments/default' title='張貼留言'/><link rel='replies' type='text/html' href='http://plainpass.com/2014/01/myname-pchome-stores-passwords-in-plaintext.html#comment-form' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/7180761039319723880'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/7180761039319723880'/><link rel='alternate' type='text/html' href='http://plainpass.com/2014/01/myname-pchome-stores-passwords-in-plaintext.html' title='「PChome Online 網路家庭-買網址」密碼沒加密！'/><author><name>Allen Own</name><uri>http://www.blogger.com/profile/07432128723498860159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgOTtJR54trZACfSZ1S-GfX8dHsYH3aLjRW6yUlr-mhSJ5cHFa2f0iPvaOYEB_AGShQpwl0tFbllzbdVooCPAh2wXx0OaEUOP6mdEB5n-yOUmnDwJC4LQ2gHlp7I4Z4Lk/s220/A2.png'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiUsNpqWfgHTXBSh3PD96WcDOEqKpSmZFR9fDFY0ZQZbpIH7Dqg02_-9qxo2sdW6QJfXR2KlCjTF7ttXtlFERk3puqOgkbqddPimhYiExO64ANVFrGoZUdE6ll3ZElrXTHcymziMNx2XsI/s72-c/pchome_myname_01.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4521309719030850665.post-5686826445901234246</id><published>2014-01-05T21:36:00.001+08:00</published><updated>2014-01-05T21:36:31.326+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Article"/><category scheme="http://www.blogger.com/atom/ns#" term="DNS"/><title type='text'>「網域名稱購買」、「DNS 代管服務」密碼沒加密系列</title><content type='html'>&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEijkIv-6f4F0gQ8Ric6Tgkz7RZtQJrwDamo7Zsr58SIgKI85FdoinGZHz9pdk3AuXP16kTxtW1sCX8yjTf9cRybJD4nSV5y2ANZndwBPsVT0QImKIxfPXssfDl3zWxzYXyXn78d3DjqkBo/s1600/DNS.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEijkIv-6f4F0gQ8Ric6Tgkz7RZtQJrwDamo7Zsr58SIgKI85FdoinGZHz9pdk3AuXP16kTxtW1sCX8yjTf9cRybJD4nSV5y2ANZndwBPsVT0QImKIxfPXssfDl3zWxzYXyXn78d3DjqkBo/s1600/DNS.png&quot; height=&quot;432&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
擁有一個好網域名稱（Domain Name）一直都是很多網路玩家的夢想。除了讓自己的網站有個更漂亮的名字之外，甚至透過買賣稀有的網域名稱賺上好大一筆。&lt;br /&gt;
&lt;br /&gt;
台灣也有非常多購買網域名稱的網站，例如「&lt;a href=&quot;http://myname.pchome.com.tw/&quot; target=&quot;_blank&quot;&gt;PChome 買網址&lt;/a&gt;」、「&lt;a href=&quot;http://www.twnic.net.tw/&quot; target=&quot;_blank&quot;&gt;TWNIC&lt;/a&gt;」、「&lt;a href=&quot;http://rs.seed.net.tw/&quot; target=&quot;_blank&quot;&gt;遠傳 seednet&lt;/a&gt;」、「&lt;a href=&quot;http://domain.hinet.net/&quot; target=&quot;_blank&quot;&gt;中華電信&lt;/a&gt;」 等等。國外也有很知名的「&lt;a href=&quot;http://www.godaddy.com/%E2%80%8E&quot; target=&quot;_blank&quot;&gt;GoDaddy&lt;/a&gt;」、「&lt;a href=&quot;https://www.enom.com/%E2%80%8E&quot; target=&quot;_blank&quot;&gt;enom&lt;/a&gt;」等。除了購買網域名稱之外，通常也會提供 DNS 代管服務，方便管理者直接在網站上修改網域設定，而不需要自己架設 DNS。&lt;br /&gt;
&lt;br /&gt;
在資訊安全的層面來看，DNS 的重要性非常非常高。日前幾個國際大型駭客攻擊都是針對 DNS，不管是入侵 DNS 修改資料、或者是綁架 DNS 導致一般使用者上網導向到惡意網站。因此此類代管服務的安全性特別重要。&lt;br /&gt;
&lt;br /&gt;
安全性做得好壞，單由使用上是無法確切得知的。但是密碼的機制呢？我們就可以好好的來看一下了。這次的 DNS 系列文我們挑選了國內外幾個大家通報的網域名稱購買、DNS 代管服務，看看他們的密碼機制有沒有好好設計。&lt;br /&gt;
&lt;br /&gt;
敬請期待！</content><link rel='replies' type='application/atom+xml' href='http://plainpass.com/feeds/5686826445901234246/comments/default' title='張貼留言'/><link rel='replies' type='text/html' href='http://plainpass.com/2014/01/plainpass-dns-series.html#comment-form' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/5686826445901234246'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/5686826445901234246'/><link rel='alternate' type='text/html' href='http://plainpass.com/2014/01/plainpass-dns-series.html' title='「網域名稱購買」、「DNS 代管服務」密碼沒加密系列'/><author><name>Allen Own</name><uri>http://www.blogger.com/profile/07432128723498860159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgOTtJR54trZACfSZ1S-GfX8dHsYH3aLjRW6yUlr-mhSJ5cHFa2f0iPvaOYEB_AGShQpwl0tFbllzbdVooCPAh2wXx0OaEUOP6mdEB5n-yOUmnDwJC4LQ2gHlp7I4Z4Lk/s220/A2.png'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEijkIv-6f4F0gQ8Ric6Tgkz7RZtQJrwDamo7Zsr58SIgKI85FdoinGZHz9pdk3AuXP16kTxtW1sCX8yjTf9cRybJD4nSV5y2ANZndwBPsVT0QImKIxfPXssfDl3zWxzYXyXn78d3DjqkBo/s72-c/DNS.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4521309719030850665.post-5472468782175456236</id><published>2013-12-14T21:20:00.000+08:00</published><updated>2013-12-14T21:20:59.236+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="PlainPass"/><category scheme="http://www.blogger.com/atom/ns#" term="Taiwan"/><title type='text'>「中華民國路跑協會」密碼沒加密！</title><content type='html'>最近非常流行「路跑」，幾乎快要成為全民運動。路跑的資訊在「&lt;a href=&quot;http://www.sportsnet.org.tw/&quot; target=&quot;_blank&quot;&gt;中華民國路跑協會&lt;/a&gt;」都有，因此也非常多人回報：路跑協會的網站疑似沒加密！&lt;br /&gt;
&lt;br /&gt;
讓我們來跟著密碼跑跑看吧！&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjWJAkicf8Kmj9wfBNl8C5CxC_mxRWDF1npJjE1Rm32pqozfUIuDSn0LVdvliPazr5P5h-VijVrIfnyUNA0m2FJTBiISosh_bfuHTHTnQfIqbhxxjoxyPnKWOM1NU234qmskiP87HOupiE/s1600/sportsnet_01.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjWJAkicf8Kmj9wfBNl8C5CxC_mxRWDF1npJjE1Rm32pqozfUIuDSn0LVdvliPazr5P5h-VijVrIfnyUNA0m2FJTBiISosh_bfuHTHTnQfIqbhxxjoxyPnKWOM1NU234qmskiP87HOupiE/s1600/sportsnet_01.png&quot; height=&quot;482&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
首先我們到「會員專區」。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi6sO_FUNQluvUT-qHbcxOqVqzyxKkZjaes_bKrTtccTdEkIgZGC7k8IZRhihRU9uMASmWw9BGVTBjbtTtFdUvGproMhcXx6triWHs4HORSotin07TWHBCdm0vV6_3HzgZFnZ-Pv3uF31I/s1600/sportsnet_02.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi6sO_FUNQluvUT-qHbcxOqVqzyxKkZjaes_bKrTtccTdEkIgZGC7k8IZRhihRU9uMASmWw9BGVTBjbtTtFdUvGproMhcXx6triWHs4HORSotin07TWHBCdm0vV6_3HzgZFnZ-Pv3uF31I/s1600/sportsnet_02.png&quot; height=&quot;482&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
網站上有關安全的說明如下：&lt;br /&gt;
&lt;blockquote class=&quot;tr_bq&quot;&gt;
中華民國路跑協對於您登錄個人資料時的保障&lt;br /&gt;
&lt;br /&gt;
您的會員資料主要是用來處理您的訂單與提供更友善的個人化線上服務，為了提供您權益的完全保障以及減少作業上的困擾，我們麻煩您盡量填寫真實的個人資料。為了讓您減少心中的不安，在此告知您，當中華民國路跑協請您填寫個人相關資料時，&lt;span style=&quot;color: red;&quot;&gt;該網頁已啟用SSL加密措施&lt;/span&gt;，若未經適當的解碼，則任何人試圖在傳輸過程中擷取您的資訊時只會取得無法讀取的亂碼。&lt;/blockquote&gt;
傳輸有加密確實很重要，而網站的左上方也掛了大大的標誌：&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgJlsk8auuy5lpNuqrHlXNIktPv4NdGQO0ySm3JQiuYoKjPRxf3biNt4qMDX0vgr_fMly7AAIHA4WAacuFCN126wTwoeNuloUIIlvr_ByQMdeMUDm6frftXXpNc6eNJp1ylvQ68fvYmP4I/s1600/sportsnet_10.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgJlsk8auuy5lpNuqrHlXNIktPv4NdGQO0ySm3JQiuYoKjPRxf3biNt4qMDX0vgr_fMly7AAIHA4WAacuFCN126wTwoeNuloUIIlvr_ByQMdeMUDm6frftXXpNc6eNJp1ylvQ68fvYmP4I/s1600/sportsnet_10.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
先不論是否是「全世界最先進的 SSL 128 bit 傳輸加密機制」，&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;SSL 要如何用得安全更是一個大學問。&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
其一，目前的新版瀏覽器針對 SSL 憑證的網站都會有安全的提示，例如 Google Chrome 瀏覽器上面所寫的：這個網站含有其他不安全的資源。主要是因為並沒有整個網站的所有物件都採用 SSL 傳輸，因此沒有 SSL 傳輸的頁面依舊是不安全的。&lt;br /&gt;
&lt;br /&gt;
其二，該網站並沒有強制在登入的頁面使用 SSL... 因此你沒有主動在網址前面加上「https」是沒用的。這種做半套的安全實在非常可惜。&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhC0NLwhSNUCwUXWCCyeSFwZgU_eiaOWE-r45xystWbCrCJn-SojuHo3FHjms2H1eZLjmmchVO1MKOPB9qHNJAj9eVxku-jxUjhrHDeUFIS5vKjVchPugntyQDxGPiKa-4Cn1TFfHF5IH0/s1600/sportsnet_09.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhC0NLwhSNUCwUXWCCyeSFwZgU_eiaOWE-r45xystWbCrCJn-SojuHo3FHjms2H1eZLjmmchVO1MKOPB9qHNJAj9eVxku-jxUjhrHDeUFIS5vKjVchPugntyQDxGPiKa-4Cn1TFfHF5IH0/s1600/sportsnet_09.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
接著我們來加入會員，填寫資料後加入。&lt;br /&gt;
讓我們的沒加密先生來加入路跑的行列吧。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjSOIHMviclc_y08BsZk-arFk9SkRefoZqMtY1Vv_gyU4gEjRX1sw752NK6oOysuMfcC7wks4bzRufU5Vp0rWbeZNy4afQDFUzUC82C9wTCgVK1tuC60IKGBQ76tUD0DXuV1SlPUHZvoHY/s1600/sportsnet_03.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjSOIHMviclc_y08BsZk-arFk9SkRefoZqMtY1Vv_gyU4gEjRX1sw752NK6oOysuMfcC7wks4bzRufU5Vp0rWbeZNy4afQDFUzUC82C9wTCgVK1tuC60IKGBQ76tUD0DXuV1SlPUHZvoHY/s1600/sportsnet_03.png&quot; height=&quot;482&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
註冊完畢後，竟然要致電或 mail 人工審核資料開通帳號。這實在是有點太過麻煩...&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi94UmkSF8UqkV3Ua7JoJMu1H_3V_xHHSPg3aSIZfZyqWC3rhWdgFEVkYkShM9v0arJfkt8ySjFFKc6RrkwYuTyhyphenhyphenD10rfOzQ57I11Nss2pdm2mPxki0nw_933Nsbz6mN6JJoK-iDUleYs/s1600/sportsnet_04.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi94UmkSF8UqkV3Ua7JoJMu1H_3V_xHHSPg3aSIZfZyqWC3rhWdgFEVkYkShM9v0arJfkt8ySjFFKc6RrkwYuTyhyphenhyphenD10rfOzQ57I11Nss2pdm2mPxki0nw_933Nsbz6mN6JJoK-iDUleYs/s1600/sportsnet_04.png&quot; height=&quot;482&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
不過沒有關係，我們依舊來測試忘記密碼的功能。&lt;br /&gt;
輸入帳號（身分證字號）、姓名、生日。這三筆資料都不難取得，實有遭到竊取的可能。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhd0kTZ2IYvVVGPN7ZlqvYvdxczbk_Ht_dJyn0rEB2tCsqalwkFo36vvfDfuBxi5xNjGNxDazhh-d3oO5qNjrj07AApPx2vGibbWAhBs-BuMmAE4csqeBXIgyll1iukeVPEzQAccQ1s1x0/s1600/sportsnet_05.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhd0kTZ2IYvVVGPN7ZlqvYvdxczbk_Ht_dJyn0rEB2tCsqalwkFo36vvfDfuBxi5xNjGNxDazhh-d3oO5qNjrj07AApPx2vGibbWAhBs-BuMmAE4csqeBXIgyll1iukeVPEzQAccQ1s1x0/s1600/sportsnet_05.png&quot; height=&quot;482&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
什麼！&lt;br /&gt;
網站竟然就這樣直接乾脆的顯示了沒加密先生原本的密碼...&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjTCWHGb_kdKySDFIwTUjLZo399hD7fZLNoIfIyjzSMFumHgpSWdLLy5r2lCFPH2FZPe_HKAhV5a0NRZFqYu3b_Y_MeUGeGm3oJaNpvV-HXzGr0kz6qy16OfXSq_RbuBQoTb6PxWTIa9qc/s1600/sportsnet_06.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjTCWHGb_kdKySDFIwTUjLZo399hD7fZLNoIfIyjzSMFumHgpSWdLLy5r2lCFPH2FZPe_HKAhV5a0NRZFqYu3b_Y_MeUGeGm3oJaNpvV-HXzGr0kz6qy16OfXSq_RbuBQoTb6PxWTIa9qc/s1600/sportsnet_06.png&quot; height=&quot;482&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
讓我們再看一次。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjIKcQaqTpltk8XMyR1lTnWmYM100fNJhPEpNakALX5oNklYp7eFmIm6lszhfEojn7q8F4xfhOPH3P1zmd_lQ4qT4wAjA2sfHCW6IjxxWZli5rqN0OM9GMHvt1Vtr-BkX8GiCYhSQJ3HE4/s1600/sportsnet_07.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjIKcQaqTpltk8XMyR1lTnWmYM100fNJhPEpNakALX5oNklYp7eFmIm6lszhfEojn7q8F4xfhOPH3P1zmd_lQ4qT4wAjA2sfHCW6IjxxWZli5rqN0OM9GMHvt1Vtr-BkX8GiCYhSQJ3HE4/s1600/sportsnet_07.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div&gt;
此外，還意外的發現...&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh-HI8Wp5Y-QBdg1NJK6ojlNSjQZgJHGfM7wMLEg_LX9yfKiYoIrL1cxhsVFqHN9A2G0Ba4fKKsQz4Frfq7hnzCJk3zZzyrMXH741kJwhPbZrB29u8KFsk1sVALnfXgfG3xD17yeH7pSuM/s1600/sportsnet_08.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh-HI8Wp5Y-QBdg1NJK6ojlNSjQZgJHGfM7wMLEg_LX9yfKiYoIrL1cxhsVFqHN9A2G0Ba4fKKsQz4Frfq7hnzCJk3zZzyrMXH741kJwhPbZrB29u8KFsk1sVALnfXgfG3xD17yeH7pSuM/s1600/sportsnet_08.png&quot; height=&quot;388&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
這測試的結果實在是令人相當哀傷：&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;「中華民國路跑協會」密碼沒加密！&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
希望該網站能夠多加強資安的強度喔！&lt;br /&gt;
&lt;br /&gt;
日期：2013-11-24&lt;br /&gt;
名稱：中華民國路跑協會&lt;br /&gt;
網址：&lt;a href=&quot;http://www.sportsnet.org.tw/&quot;&gt;http://www.sportsnet.org.tw/&lt;/a&gt;&lt;br /&gt;
結果：密碼沒加密
&lt;br /&gt;
&lt;br /&gt;
感謝&amp;nbsp;Gdx Wu、Yc Li、罐子 的爆料！&lt;/div&gt;
</content><link rel='replies' type='application/atom+xml' href='http://plainpass.com/feeds/5472468782175456236/comments/default' title='張貼留言'/><link rel='replies' type='text/html' href='http://plainpass.com/2013/12/sportsnet-stores-passwords-in-plaintext.html#comment-form' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/5472468782175456236'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/5472468782175456236'/><link rel='alternate' type='text/html' href='http://plainpass.com/2013/12/sportsnet-stores-passwords-in-plaintext.html' title='「中華民國路跑協會」密碼沒加密！'/><author><name>Allen Own</name><uri>http://www.blogger.com/profile/07432128723498860159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgOTtJR54trZACfSZ1S-GfX8dHsYH3aLjRW6yUlr-mhSJ5cHFa2f0iPvaOYEB_AGShQpwl0tFbllzbdVooCPAh2wXx0OaEUOP6mdEB5n-yOUmnDwJC4LQ2gHlp7I4Z4Lk/s220/A2.png'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjWJAkicf8Kmj9wfBNl8C5CxC_mxRWDF1npJjE1Rm32pqozfUIuDSn0LVdvliPazr5P5h-VijVrIfnyUNA0m2FJTBiISosh_bfuHTHTnQfIqbhxxjoxyPnKWOM1NU234qmskiP87HOupiE/s72-c/sportsnet_01.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4521309719030850665.post-6683072882542640675</id><published>2013-11-24T17:03:00.001+08:00</published><updated>2013-11-24T17:03:34.331+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="PlainPass"/><category scheme="http://www.blogger.com/atom/ns#" term="Submission"/><category scheme="http://www.blogger.com/atom/ns#" term="Taiwan"/><title type='text'>「黑貓宅急便」密碼沒加密？</title><content type='html'>「&lt;a href=&quot;http://www.t-cat.com.tw/&quot; target=&quot;_blank&quot;&gt;黑貓宅急便&lt;/a&gt;」是國內配送物流業，會員服務提供訂單管理、常用聯絡人等服務，想必有許多個人資料。&lt;br /&gt;
&lt;br /&gt;
有服務的地方就有帳號，有帳號的地方就有密碼。&lt;br /&gt;
到底黑貓宅急便密碼有沒有加密呢？讓我們來看看。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhSY3v-RROIfTNKGqvHPXGWIC3x4iWvPaJ7B6yQwQ0sxiNOjX0QS_eixBZZfnwLGFSpWXYwOvFzzgjeE4KJPNLQFohTywawAQbJOO9k950jF22g4ZobrSYthERaqoL8qk6pK2LK5oWCKGI/s1600/t-cat_00.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhSY3v-RROIfTNKGqvHPXGWIC3x4iWvPaJ7B6yQwQ0sxiNOjX0QS_eixBZZfnwLGFSpWXYwOvFzzgjeE4KJPNLQFohTywawAQbJOO9k950jF22g4ZobrSYthERaqoL8qk6pK2LK5oWCKGI/s1600/t-cat_00.jpg&quot; height=&quot;482&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
先來試試看密碼忘記的流程吧！&lt;br /&gt;
&lt;br /&gt;
1.按下會員登入&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiJNfGkPnouPmelKwLcD-lG8_SSpo9-P3c2fQP7gOEIGYd52Fx4u1PZtvVTCI5ghfLFa4OCYspzUeoEYAhDhbB36y_HHBs4j1f5XwnauXJp7ZN-paki1P5tELS0GWT_yv_sjX8TVtFGdUk/s1600/t-cat_01.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiJNfGkPnouPmelKwLcD-lG8_SSpo9-P3c2fQP7gOEIGYd52Fx4u1PZtvVTCI5ghfLFa4OCYspzUeoEYAhDhbB36y_HHBs4j1f5XwnauXJp7ZN-paki1P5tELS0GWT_yv_sjX8TVtFGdUk/s1600/t-cat_01.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
2. 點選忘記密碼&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgf_GPCDtw2EqxzFmlqtsO7qZUNN3PIg-MM7jZjrlNcIrfeHLhRj-3FNXcb6tpW6i_uliBMxcHZRs3sTBpDxJ_FXFfw0BNHb97YDuKBP-z_vcqfJA4QyAJdI0NGY0KZMwY95yNxfB-HG0A/s1600/t-cat_02.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em; text-align: center;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgf_GPCDtw2EqxzFmlqtsO7qZUNN3PIg-MM7jZjrlNcIrfeHLhRj-3FNXcb6tpW6i_uliBMxcHZRs3sTBpDxJ_FXFfw0BNHb97YDuKBP-z_vcqfJA4QyAJdI0NGY0KZMwY95yNxfB-HG0A/s1600/t-cat_02.png&quot; height=&quot;464&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
3. 填寫會員帳號、email&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgXTo8If-2vBYRV_eI0deVFeitEl3uuOtD301sY5MZ4oAvax9Iigbnb8EdmdeDo2LRgrpO_xty-s2mxqgRkS8n4_0ggtb7eKEAEkEtRX5GS36aZijKX-p7wV-WaAtt_9icuOAThed_ef8Q/s1600/t-cat_03.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em; text-align: center;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgXTo8If-2vBYRV_eI0deVFeitEl3uuOtD301sY5MZ4oAvax9Iigbnb8EdmdeDo2LRgrpO_xty-s2mxqgRkS8n4_0ggtb7eKEAEkEtRX5GS36aZijKX-p7wV-WaAtt_9icuOAThed_ef8Q/s1600/t-cat_03.png&quot; height=&quot;394&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
4. 帳號密碼已送出&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg2Bce84sfvhr3dk9ykUsQNuRoGTTxWDzIdJjxt-6ekyWtSc6kLUlP0qR8czs5K1kTB5J_XfnkA0qeNiFryIhxwXVJzq9OO44r-MfKxVQ9zl0caJSw4FRCUSZdVP9fWX-1qVAUSxQt06OA/s1600/t-cat_04.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em; text-align: center;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg2Bce84sfvhr3dk9ykUsQNuRoGTTxWDzIdJjxt-6ekyWtSc6kLUlP0qR8czs5K1kTB5J_XfnkA0qeNiFryIhxwXVJzq9OO44r-MfKxVQ9zl0caJSw4FRCUSZdVP9fWX-1qVAUSxQt06OA/s1600/t-cat_04.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
5. 非常快速的送過來了，黑貓宅急便沒有加密&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjJGcuobW-GcLB_mvkOymZGWEnAVdSjgBtuVvTl_ahgbLWRoiib9xUlvBVOTm0ob-fuHIYlgjarwsd6FfNHzhiw4taqTlAybFKf34UN2y-ndXpgiQW71LUn_nZPjTBwx6c89mamYMCFXI8/s1600/t-cat_05.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em; text-align: center;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjJGcuobW-GcLB_mvkOymZGWEnAVdSjgBtuVvTl_ahgbLWRoiib9xUlvBVOTm0ob-fuHIYlgjarwsd6FfNHzhiw4taqTlAybFKf34UN2y-ndXpgiQW71LUn_nZPjTBwx6c89mamYMCFXI8/s1600/t-cat_05.png&quot; height=&quot;374&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
但在其中「個人資料保護聲明」的部份說了：&lt;br /&gt;
&lt;blockquote class=&quot;tr_bq&quot;&gt;
六、資料安全及保護方法&lt;br /&gt;我們以Secure Sockets Layer（SSL）機制進行資料傳輸的加密，並已加裝防火牆防止不法入侵，避免您的個人資料遭到非法存取。我們並應用亂碼化方式儲存密碼，以確保您的密碼不會遭到非法竊取。&lt;/blockquote&gt;
&lt;div&gt;
黑貓並沒有說明「亂碼化」的方式為何，但是若使用者可以取回原本的密碼，就代表密碼機制是「可逆」的演算法，駭客若入侵也依舊可以解密取得所有使用者的帳號密碼。&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
希望黑貓宅急便可以改成「不可逆演算法」將密碼加密。&lt;/div&gt;
&lt;br /&gt;
日期：2013-11-18&lt;br /&gt;
名稱：黑貓宅急便&lt;br /&gt;
網址：&lt;a href=&quot;http://www.t-cat.com.tw/&quot;&gt;http://www.t-cat.com.tw/&lt;/a&gt;&lt;br /&gt;
結果：密碼沒加密
&lt;br /&gt;
&lt;br /&gt;
感謝 Davihuan 的爆料，梨頭貝兒 的投稿！</content><link rel='replies' type='application/atom+xml' href='http://plainpass.com/feeds/6683072882542640675/comments/default' title='張貼留言'/><link rel='replies' type='text/html' href='http://plainpass.com/2013/11/t-cat-stores-passwords-in-plaintext.html#comment-form' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/6683072882542640675'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/6683072882542640675'/><link rel='alternate' type='text/html' href='http://plainpass.com/2013/11/t-cat-stores-passwords-in-plaintext.html' title='「黑貓宅急便」密碼沒加密？'/><author><name>Allen Own</name><uri>http://www.blogger.com/profile/07432128723498860159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgOTtJR54trZACfSZ1S-GfX8dHsYH3aLjRW6yUlr-mhSJ5cHFa2f0iPvaOYEB_AGShQpwl0tFbllzbdVooCPAh2wXx0OaEUOP6mdEB5n-yOUmnDwJC4LQ2gHlp7I4Z4Lk/s220/A2.png'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhSY3v-RROIfTNKGqvHPXGWIC3x4iWvPaJ7B6yQwQ0sxiNOjX0QS_eixBZZfnwLGFSpWXYwOvFzzgjeE4KJPNLQFohTywawAQbJOO9k950jF22g4ZobrSYthERaqoL8qk6pK2LK5oWCKGI/s72-c/t-cat_00.jpg" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4521309719030850665.post-6135116458489920776</id><published>2013-11-23T21:27:00.000+08:00</published><updated>2013-11-23T21:27:29.543+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="PlainPass"/><category scheme="http://www.blogger.com/atom/ns#" term="Shopping"/><category scheme="http://www.blogger.com/atom/ns#" term="Submission"/><category scheme="http://www.blogger.com/atom/ns#" term="Taiwan"/><title type='text'>「爽購 songogo」密碼沒加密！</title><content type='html'>感謝 tonypai 的投稿！&lt;br /&gt;
&lt;br /&gt;
「&lt;a href=&quot;https://www.songogo.com/&quot; target=&quot;_blank&quot;&gt;爽購&lt;/a&gt;」是提供淘寶跨海購物的平台，服務的內容牽扯到現上金流的交易，但是在會員忘記密碼的處理上卻沒做加密，大喇喇的以明文顯示。&lt;br /&gt;
&lt;br /&gt;
點選忘記密碼&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiQNUgwldkBNFAYOuAULHe8gbrpavQ6_jeaFHt4jEoyirvO-zqMVsZFkPgjlpRBmBPFeCNwuepcun6k3fg_0i0PZRr16PqC663C_gd6JRpsnVNC4rDlFMGxqKS-Q9WQoQhIXqmgNh0TIQc/s1600/songogo1.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiQNUgwldkBNFAYOuAULHe8gbrpavQ6_jeaFHt4jEoyirvO-zqMVsZFkPgjlpRBmBPFeCNwuepcun6k3fg_0i0PZRr16PqC663C_gd6JRpsnVNC4rDlFMGxqKS-Q9WQoQhIXqmgNh0TIQc/s640/songogo1.jpg&quot; height=&quot;190&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
輸入會員email&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhM9Kcpd55JnIQPMaJYgWSD6krvDRwgzu1cjMko-EEvv7bQzZXj3tWuLc0-vsEagV45EJ6-1JqyJxIVkyqyypeqC3DRdwMhkd7-iOgzRLKQLTVeiWn3U-HfwnZ3bZe1zSO26mCpqiSf0Ko/s1600/songogo2.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em; text-align: center;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhM9Kcpd55JnIQPMaJYgWSD6krvDRwgzu1cjMko-EEvv7bQzZXj3tWuLc0-vsEagV45EJ6-1JqyJxIVkyqyypeqC3DRdwMhkd7-iOgzRLKQLTVeiWn3U-HfwnZ3bZe1zSO26mCpqiSf0Ko/s640/songogo2.jpg&quot; height=&quot;350&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
信件寄出&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiKxr-oyF_zRglStYEP8zsUp-l2WFVWp2ENSIX2mZ2NL4isv0W_YBwIT4gPZ4aUfuP6fFoFDYabtgfnzLtM_inf84so0e1VJdpFoEKAXCq1I60yaZMhH-_sCqv3UCtk17mDnm3x0B8gR7E/s1600/songogo3.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em; text-align: center;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiKxr-oyF_zRglStYEP8zsUp-l2WFVWp2ENSIX2mZ2NL4isv0W_YBwIT4gPZ4aUfuP6fFoFDYabtgfnzLtM_inf84so0e1VJdpFoEKAXCq1I60yaZMhH-_sCqv3UCtk17mDnm3x0B8gR7E/s1600/songogo3.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
收到明文密碼...&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhXZi00XYI2Ihn0kE9wPb1QBmyYzrh8xndWKgsden9uymFaPePhtV4oaqUBP9K1xZ9_sLTphCQbvP6VJZZCZyybq_lctmI0S4X195Uo0mdI7Ks39hoF7ZLQ0IGFgc9_7VfEmsSiU22dCXA/s1600/songogo4.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em; text-align: center;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhXZi00XYI2Ihn0kE9wPb1QBmyYzrh8xndWKgsden9uymFaPePhtV4oaqUBP9K1xZ9_sLTphCQbvP6VJZZCZyybq_lctmI0S4X195Uo0mdI7Ks39hoF7ZLQ0IGFgc9_7VfEmsSiU22dCXA/s1600/songogo4.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
日期：2013-11-16&lt;br /&gt;
名稱：爽購&lt;br /&gt;
網址：&lt;a href=&quot;https://www.songogo.com/&quot;&gt;https://www.songogo.com/&lt;/a&gt;&lt;br /&gt;
結果：密碼沒加密&lt;br /&gt;
&lt;br /&gt;
本文感謝 tonypai 的投稿！</content><link rel='replies' type='application/atom+xml' href='http://plainpass.com/feeds/6135116458489920776/comments/default' title='張貼留言'/><link rel='replies' type='text/html' href='http://plainpass.com/2013/11/songogo.html#comment-form' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/6135116458489920776'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/6135116458489920776'/><link rel='alternate' type='text/html' href='http://plainpass.com/2013/11/songogo.html' title='「爽購 songogo」密碼沒加密！'/><author><name>Allen Own</name><uri>http://www.blogger.com/profile/07432128723498860159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgOTtJR54trZACfSZ1S-GfX8dHsYH3aLjRW6yUlr-mhSJ5cHFa2f0iPvaOYEB_AGShQpwl0tFbllzbdVooCPAh2wXx0OaEUOP6mdEB5n-yOUmnDwJC4LQ2gHlp7I4Z4Lk/s220/A2.png'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiQNUgwldkBNFAYOuAULHe8gbrpavQ6_jeaFHt4jEoyirvO-zqMVsZFkPgjlpRBmBPFeCNwuepcun6k3fg_0i0PZRr16PqC663C_gd6JRpsnVNC4rDlFMGxqKS-Q9WQoQhIXqmgNh0TIQc/s72-c/songogo1.jpg" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4521309719030850665.post-5877897168378911947</id><published>2013-11-13T21:29:00.000+08:00</published><updated>2013-11-13T21:29:37.820+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Hosting"/><category scheme="http://www.blogger.com/atom/ns#" term="PlainPass"/><category scheme="http://www.blogger.com/atom/ns#" term="Taiwan"/><title type='text'>「智邦生活館 網站代管」密碼沒加密！</title><content type='html'>「&lt;a href=&quot;http://www.url.com.tw/&quot; target=&quot;_blank&quot;&gt;智邦生活館&lt;/a&gt;」不知道大家有聽過嗎？我相信只要是有一定網齡的人都一定用過他們的服務。他們提供 Email、網站虛擬主機代管等等。&lt;br /&gt;
&lt;br /&gt;
今天要講的問題是智邦生活館的網站代管服務。&lt;br /&gt;
&lt;a href=&quot;https://hosting.url.com.tw/vhadmin/&quot;&gt;https://hosting.url.com.tw/vhadmin/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi-aCt2-Pzyi9AibFD-uejc0bQ8Q0oVoo43QOdbg59gLVdIEhKTZliZx1Az5YQDNeF3XFjTSSaJ9Do_ru0RIc0xZnynBXWrmWtNFyU6Pn-fBe8N4-hMu-iX79HETiOihfw4cqENmyie49c/s1600/%E5%9C%96%E7%89%87+001.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;190&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi-aCt2-Pzyi9AibFD-uejc0bQ8Q0oVoo43QOdbg59gLVdIEhKTZliZx1Az5YQDNeF3XFjTSSaJ9Do_ru0RIc0xZnynBXWrmWtNFyU6Pn-fBe8N4-hMu-iX79HETiOihfw4cqENmyie49c/s640/%E5%9C%96%E7%89%87+001.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
首先我們點選「管理登入」&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhu8fODoY0butVoJRt0lu5sDYyYrLbEtpi9xBAzPyBSQcEKaVxj61D9bNM-g6MK_UgOh3_F7Cqqhx1__kxUOvHeVNnH9MjAWwFRBjo2347UIbZMMBAvSf5reXl0_D8M0aJ1N-0zPs0xDyI/s1600/%E5%9C%96%E7%89%87+002.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;224&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhu8fODoY0butVoJRt0lu5sDYyYrLbEtpi9xBAzPyBSQcEKaVxj61D9bNM-g6MK_UgOh3_F7Cqqhx1__kxUOvHeVNnH9MjAWwFRBjo2347UIbZMMBAvSf5reXl0_D8M0aJ1N-0zPs0xDyI/s640/%E5%9C%96%E7%89%87+002.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
點選「忘記密碼」後，輸入管理者電子郵件信箱。&lt;br /&gt;
看著「密碼查詢」的按鈕，好像已經可以知道答案。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhvY97sIboQXqHGBpa8kvFx-lj9WJK2xdvri18-xl6gZic4KEaOAgnp51lLlS7E4NnksIrEsoTT5FHgTBWiiSa3ceLL6pc44nYJILHRDQhTnRba_bwVIJM2fPg2tgsGaE9F0632kpG6hG8/s1600/%E5%9C%96%E7%89%87+003.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhvY97sIboQXqHGBpa8kvFx-lj9WJK2xdvri18-xl6gZic4KEaOAgnp51lLlS7E4NnksIrEsoTT5FHgTBWiiSa3ceLL6pc44nYJILHRDQhTnRba_bwVIJM2fPg2tgsGaE9F0632kpG6hG8/s1600/%E5%9C%96%E7%89%87+003.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&amp;nbsp;「已將您的密碼寄到管理者信箱中。」&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgIYNWznboekl9tU64P-sqQuvriYPXtQldEvoFVGPKTyax6O_Lu1USZMrR441hQtr_j_nEYOqPgHKm5_3wGQmI9zGalBUydpIlsSeT-DzUJ2r1Sui7jOwOiVWyhkTdvZ3jeL7AX6t2ppL8/s1600/%E5%9C%96%E7%89%87+004.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgIYNWznboekl9tU64P-sqQuvriYPXtQldEvoFVGPKTyax6O_Lu1USZMrR441hQtr_j_nEYOqPgHKm5_3wGQmI9zGalBUydpIlsSeT-DzUJ2r1Sui7jOwOiVWyhkTdvZ3jeL7AX6t2ppL8/s1600/%E5%9C%96%E7%89%87+004.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
信箱果然在一分鐘後收到管理者的密碼。&lt;br /&gt;
為了保護爆料者，我們把密碼遮起來，歡迎大家也試試看。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiYL9-GEpXsYosktq6elaokYxg_JmkcEGcYEADSgz1yNSRVlovZPAgc9fpEn8uiSR3_rtcqcs0Mws8y4FlOGGj_yvV2ljbfQqVVE2MG-l000ewMBB1h5JrVjcWV4oxl3mwuRH47NzDgyDo/s1600/%E5%9C%96%E7%89%87+006+2.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiYL9-GEpXsYosktq6elaokYxg_JmkcEGcYEADSgz1yNSRVlovZPAgc9fpEn8uiSR3_rtcqcs0Mws8y4FlOGGj_yvV2ljbfQqVVE2MG-l000ewMBB1h5JrVjcWV4oxl3mwuRH47NzDgyDo/s1600/%E5%9C%96%E7%89%87+006+2.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;「智邦生活館網站代管」密碼沒加密！&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
日期：2013-11-12&lt;br /&gt;
名稱：智邦生活館網站代管&lt;br /&gt;
網址：&lt;a href=&quot;https://hosting.url.com.tw/vhadmin/&quot;&gt;https://hosting.url.com.tw/vhadmin/&lt;/a&gt;&lt;br /&gt;
結果：密碼沒加密
&lt;br /&gt;
&lt;br /&gt;
感謝 GD、黃小黃 的爆料！</content><link rel='replies' type='application/atom+xml' href='http://plainpass.com/feeds/5877897168378911947/comments/default' title='張貼留言'/><link rel='replies' type='text/html' href='http://plainpass.com/2013/11/url-hosting-stores-passwords-in-plaintext.html#comment-form' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/5877897168378911947'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/5877897168378911947'/><link rel='alternate' type='text/html' href='http://plainpass.com/2013/11/url-hosting-stores-passwords-in-plaintext.html' title='「智邦生活館 網站代管」密碼沒加密！'/><author><name>Allen Own</name><uri>http://www.blogger.com/profile/07432128723498860159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgOTtJR54trZACfSZ1S-GfX8dHsYH3aLjRW6yUlr-mhSJ5cHFa2f0iPvaOYEB_AGShQpwl0tFbllzbdVooCPAh2wXx0OaEUOP6mdEB5n-yOUmnDwJC4LQ2gHlp7I4Z4Lk/s220/A2.png'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi-aCt2-Pzyi9AibFD-uejc0bQ8Q0oVoo43QOdbg59gLVdIEhKTZliZx1Az5YQDNeF3XFjTSSaJ9Do_ru0RIc0xZnynBXWrmWtNFyU6Pn-fBe8N4-hMu-iX79HETiOihfw4cqENmyie49c/s72-c/%E5%9C%96%E7%89%87+001.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4521309719030850665.post-6701194884531520315</id><published>2013-11-11T22:24:00.000+08:00</published><updated>2013-11-11T22:32:51.530+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="PlainPass"/><category scheme="http://www.blogger.com/atom/ns#" term="Taiwan"/><title type='text'>「財訊雜誌」密碼沒加密！</title><content type='html'>「&lt;a href=&quot;http://www.wealth.com.tw/&quot; target=&quot;_blank&quot;&gt;財訊雜誌&lt;/a&gt;」是台灣很資深知名的媒體，目前也有線上服務。&lt;br /&gt;
&lt;br /&gt;
有關個資收集的說明&lt;br /&gt;
&lt;blockquote class=&quot;tr_bq&quot;&gt;
一、財訊網站對網友個人資料的收集，謹遵守中華民國「電腦處理個人資料保護法」之規範。未經主管機關許可及網友同意，財訊網站不會以電腦蒐集網友個人資料。&lt;/blockquote&gt;
&lt;div&gt;
讓我們來看看財訊的網站...&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgRqaE8VO_HMroR9SJc8-se8CT9G5v95KGlhK9GfjjjqwS7cCFTno4rQ09KUVCM5qsgvarbCVHrYnCQk7aHIgMwavvPhZdxOaErBiZ_-C0LXUgFWPZeyvwNmKHYChfQ7O7UfB_F8uW_OXU/s1600/wealth_01.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;482&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgRqaE8VO_HMroR9SJc8-se8CT9G5v95KGlhK9GfjjjqwS7cCFTno4rQ09KUVCM5qsgvarbCVHrYnCQk7aHIgMwavvPhZdxOaErBiZ_-C0LXUgFWPZeyvwNmKHYChfQ7O7UfB_F8uW_OXU/s640/wealth_01.jpg&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
同意會員條款。&lt;br /&gt;
我有的時候很好奇到底多少人會好好的看會員條款，尤其是國外的網站。XD&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjOwtjXlA8D2AbEByEcbigNR8bZSQwJSVJhy3-J3aXrpXArNwr45mlX2clphRWJMXlw3ul4lek3D5QhFLpHnC94ljcRTxBTm9zMjCjWrifByc61GOmfp6_NUxCsFFKEWbpm3D00bm7hyphenhyphenr4/s1600/wealth_02.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;482&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjOwtjXlA8D2AbEByEcbigNR8bZSQwJSVJhy3-J3aXrpXArNwr45mlX2clphRWJMXlw3ul4lek3D5QhFLpHnC94ljcRTxBTm9zMjCjWrifByc61GOmfp6_NUxCsFFKEWbpm3D00bm7hyphenhyphenr4/s640/wealth_02.jpg&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
請我們的沒加密小姐來註冊囉！&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEinvBSzmCmRu5hMeNZ0qC0fHXYiFkotVBZDcldabZKJREKadzrBVMGyjxNA7NmfWf0sxekpfBfiYVrQUTJQk5hSU2FYYwd5UuCQ9Y7xW1MZJH6zYV517ZkaqHHGQrSZcnntQg1rLPEbzHQ/s1600/wealth_03.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;482&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEinvBSzmCmRu5hMeNZ0qC0fHXYiFkotVBZDcldabZKJREKadzrBVMGyjxNA7NmfWf0sxekpfBfiYVrQUTJQk5hSU2FYYwd5UuCQ9Y7xW1MZJH6zYV517ZkaqHHGQrSZcnntQg1rLPEbzHQ/s640/wealth_03.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
註冊完畢&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEifwUE9tzGTWlozJcWnyzPuDOHfmiAeZezFxrqV9X2tumw7saFIV0kyeynyowRyrXmMrYsF7ZqmXqDgTL5JEdyf_3K-fEpM2sQcxXez9EiWPspsoVWGY92PwozmXTYqNZlGDn4i0a6FZBM/s1600/wealth_04.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;482&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEifwUE9tzGTWlozJcWnyzPuDOHfmiAeZezFxrqV9X2tumw7saFIV0kyeynyowRyrXmMrYsF7ZqmXqDgTL5JEdyf_3K-fEpM2sQcxXez9EiWPspsoVWGY92PwozmXTYqNZlGDn4i0a6FZBM/s640/wealth_04.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
忘記密碼一下...&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiHRg8oanLznxULxvo6HNHpd8jvSHTrOmGshJnaLUAR5QDzIgc0zp5ovypaBKWuOsnNH_OT1cKEE49sJd6Hzr3gMA6aUovrYXl4EkGzkTASE6rG5xA0Hwre_d9jGl4NnI2WzN1SxSuEvQA/s1600/wealth_05.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;482&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiHRg8oanLznxULxvo6HNHpd8jvSHTrOmGshJnaLUAR5QDzIgc0zp5ovypaBKWuOsnNH_OT1cKEE49sJd6Hzr3gMA6aUovrYXl4EkGzkTASE6rG5xA0Hwre_d9jGl4NnI2WzN1SxSuEvQA/s640/wealth_05.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
「密碼信件已經成功寄出！」&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjGL-CkzCvDCiZ4WhkJZf22nudNJymPzQ1MDAKBdwoJCPpxVu9aCLlxVAQFuhLFcdPnN1rbaMmzGhJYmiO38dFk7mtqdKkPTIbYJL99_WfwjAoAaYggBfPSU0DkRQMePHQ9T3m7HlbKL5Y/s1600/wealth_06.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjGL-CkzCvDCiZ4WhkJZf22nudNJymPzQ1MDAKBdwoJCPpxVu9aCLlxVAQFuhLFcdPnN1rbaMmzGhJYmiO38dFk7mtqdKkPTIbYJL99_WfwjAoAaYggBfPSU0DkRQMePHQ9T3m7HlbKL5Y/s640/wealth_06.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
順利的收到我們的密碼啦！&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgNTggVbxQ5SKf8ZU2eb6dM2lKnonkbrSipVfHESFvYhfbZfG3oY0eqE5czj2xA_wOnyPfndEjXQhMbRd70nFw0Xfz2Dmt9sDSsq6oiH2PMV-LxJz4qI0V8Na8aFzab2JPmmdrJLP9TDM4/s1600/wealth_07.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;442&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgNTggVbxQ5SKf8ZU2eb6dM2lKnonkbrSipVfHESFvYhfbZfG3oY0eqE5czj2xA_wOnyPfndEjXQhMbRd70nFw0Xfz2Dmt9sDSsq6oiH2PMV-LxJz4qI0V8Na8aFzab2JPmmdrJLP9TDM4/s640/wealth_07.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;「財訊雜誌」密碼沒加密！&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;br /&gt;
日期：2013-11-11&lt;br /&gt;
名稱：財訊雜誌&lt;br /&gt;
網址：&lt;a href=&quot;http://www.wealth.com.tw/&quot; target=&quot;_blank&quot;&gt;http://www.wealth.com.tw/&lt;/a&gt;&lt;br /&gt;
結果：密碼沒加密
&lt;br /&gt;
&lt;br /&gt;
感謝&amp;nbsp;Inndy&amp;nbsp;的爆料！</content><link rel='replies' type='application/atom+xml' href='http://plainpass.com/feeds/6701194884531520315/comments/default' title='張貼留言'/><link rel='replies' type='text/html' href='http://plainpass.com/2013/11/wealth-stores-passwords-in-plaintext.html#comment-form' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/6701194884531520315'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/6701194884531520315'/><link rel='alternate' type='text/html' href='http://plainpass.com/2013/11/wealth-stores-passwords-in-plaintext.html' title='「財訊雜誌」密碼沒加密！'/><author><name>Allen Own</name><uri>http://www.blogger.com/profile/07432128723498860159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgOTtJR54trZACfSZ1S-GfX8dHsYH3aLjRW6yUlr-mhSJ5cHFa2f0iPvaOYEB_AGShQpwl0tFbllzbdVooCPAh2wXx0OaEUOP6mdEB5n-yOUmnDwJC4LQ2gHlp7I4Z4Lk/s220/A2.png'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgRqaE8VO_HMroR9SJc8-se8CT9G5v95KGlhK9GfjjjqwS7cCFTno4rQ09KUVCM5qsgvarbCVHrYnCQk7aHIgMwavvPhZdxOaErBiZ_-C0LXUgFWPZeyvwNmKHYChfQ7O7UfB_F8uW_OXU/s72-c/wealth_01.jpg" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4521309719030850665.post-1955353919029881999</id><published>2013-11-09T21:35:00.002+08:00</published><updated>2014-01-23T00:02:55.590+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="PlainPass"/><category scheme="http://www.blogger.com/atom/ns#" term="Shopping"/><category scheme="http://www.blogger.com/atom/ns#" term="Taiwan"/><title type='text'>「ASAP 閃電購物網」密碼沒加密？ [更新]</title><content type='html'>&lt;br /&gt;
Update: 經網友通報，ASAP 閃電購物網已經將密碼機制改為「重設密碼」。&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
同為 uitox 的新網站「&lt;a href=&quot;http://www.asap.com.tw/&quot; target=&quot;_blank&quot;&gt;ASAP 閃電購物網&lt;/a&gt;」，有著跟「&lt;a href=&quot;http://www.igarden.com/&quot; target=&quot;_blank&quot;&gt;igarden&lt;/a&gt;」一樣的設計，詳見&lt;a href=&quot;http://plainpass.com/2013/11/uitox-igarden-stores-passwords-in-plaintext.html&quot; target=&quot;_blank&quot;&gt;前文&lt;/a&gt;。&lt;br /&gt;
之前已經有通報過 uitox，就等待他們的修改囉。&lt;br /&gt;
&lt;br /&gt;
我們廢話不多說，直接看圖。&lt;br /&gt;
&lt;br /&gt;
首頁上給使用這的註冊頁面很不友善，你必須得下訂單才有機會註冊。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhBzPSc9INC70CDnM9n_Mnz0fjvYnfr-zOrQ5SMYd2wEVGX6TQuagrxvKYNGNUJmjGB01TDdiKW2NaDrWKMSXZciR8VI8rif-cNSvnRBqPVHyJCMwpD2eeLQIoI1m6LlKp2IIFkkcDKsFk/s1600/ASAP_01.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhBzPSc9INC70CDnM9n_Mnz0fjvYnfr-zOrQ5SMYd2wEVGX6TQuagrxvKYNGNUJmjGB01TDdiKW2NaDrWKMSXZciR8VI8rif-cNSvnRBqPVHyJCMwpD2eeLQIoI1m6LlKp2IIFkkcDKsFk/s640/ASAP_01.jpg&quot; height=&quot;394&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
點選「沒有密碼」就會跳到註冊頁面。這 UX 設計真的很特別...&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi2ML6xjN6Sh9KejNu9p0M8wvRr5ynVGGMX35yNhhPRrtShXIcDsqiUiRIswjOcl1AN2Z6tzUZhWRYNSoMACNSEzpBTAm0np6HlkJsCXifTvvSuMZ5KfzTKYYOBtZfnnoQFV8ZEViKTEYo/s1600/ASAP_02.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi2ML6xjN6Sh9KejNu9p0M8wvRr5ynVGGMX35yNhhPRrtShXIcDsqiUiRIswjOcl1AN2Z6tzUZhWRYNSoMACNSEzpBTAm0np6HlkJsCXifTvvSuMZ5KfzTKYYOBtZfnnoQFV8ZEViKTEYo/s640/ASAP_02.png&quot; height=&quot;394&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
建立新帳戶&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhFINaL-q3qnODEj_F1wnY7abNiHPAEcb_hdMqmWne09mzCVps3Lh1FT6tEgBm5toCdzwgNqBu3tnJHnCoQ9qSn8PZVoQhVKefY2A9TPBseqR1YVzw0ikmCLN0JT5gtEEJ2DwyXe6e5Oqs/s1600/ASAP_03.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhFINaL-q3qnODEj_F1wnY7abNiHPAEcb_hdMqmWne09mzCVps3Lh1FT6tEgBm5toCdzwgNqBu3tnJHnCoQ9qSn8PZVoQhVKefY2A9TPBseqR1YVzw0ikmCLN0JT5gtEEJ2DwyXe6e5Oqs/s640/ASAP_03.png&quot; height=&quot;394&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
建立完畢後，我們嘗試「忘記密碼」。&lt;br /&gt;
&lt;br /&gt;
上面清楚寫著「我們將會寄發密碼給您」。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjp4vAx4zDySQ_9oRcSXVXj312HEMZaQsXBY0g0U0FVuptm9nf41pqzTd3VplSlOf9ePltF4lUWPi9C5PzjLUYg3q2Q8PYfyn9i6Vz95VIGOpm3LkFMrI0hCVfWsbNgwJ_nBvDASPOIjNY/s1600/ASAP_04.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjp4vAx4zDySQ_9oRcSXVXj312HEMZaQsXBY0g0U0FVuptm9nf41pqzTd3VplSlOf9ePltF4lUWPi9C5PzjLUYg3q2Q8PYfyn9i6Vz95VIGOpm3LkFMrI0hCVfWsbNgwJ_nBvDASPOIjNY/s640/ASAP_04.png&quot; height=&quot;394&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&amp;nbsp;密碼已發送&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiwMbr3ddnRpeO6D3POBW7PWfyARUrqLAyq20ZePgxsCfSQtypfhruAshVdMORkc8KIPl8W_7WP8xj83MgX0lQQ4JAWfh7N27fxzvFfQBJmNA4TYa8zyZy3oRe1VGgbuixOGz2OORas5-w/s1600/ASAP_05.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiwMbr3ddnRpeO6D3POBW7PWfyARUrqLAyq20ZePgxsCfSQtypfhruAshVdMORkc8KIPl8W_7WP8xj83MgX0lQQ4JAWfh7N27fxzvFfQBJmNA4TYa8zyZy3oRe1VGgbuixOGz2OORas5-w/s1600/ASAP_05.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
清楚的收到密碼囉！&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh1kdBgLZL60lNWXYWVlLVm-sL1QbXI2SDCwzETUMhPm2RvN6rq88QE_q5ueY8AwvATSv2s-Gupjv-allpgdN42txuQLCuy05k1nUNNSfhd1a9Dqpz-bYnCnb-MfhofiHwtrkWdthcXlas/s1600/ASAP_06.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh1kdBgLZL60lNWXYWVlLVm-sL1QbXI2SDCwzETUMhPm2RvN6rq88QE_q5ueY8AwvATSv2s-Gupjv-allpgdN42txuQLCuy05k1nUNNSfhd1a9Dqpz-bYnCnb-MfhofiHwtrkWdthcXlas/s640/ASAP_06.png&quot; height=&quot;534&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
ASAP 閃電購物網，取回密碼也 ASAP。&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
日期：2013-11-09&lt;br /&gt;
名稱：ASAP 閃電購物網&lt;br /&gt;
網址：&lt;a href=&quot;http://www.asap.com.tw/&quot;&gt;http://www.asap.com.tw&lt;/a&gt;&lt;br /&gt;
結果：密碼沒加密
&lt;br /&gt;
&lt;br /&gt;
感謝 Richer Yang 的爆料！</content><link rel='replies' type='application/atom+xml' href='http://plainpass.com/feeds/1955353919029881999/comments/default' title='張貼留言'/><link rel='replies' type='text/html' href='http://plainpass.com/2013/11/asap-stores-passwords-in-plaintext.html#comment-form' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/1955353919029881999'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/1955353919029881999'/><link rel='alternate' type='text/html' href='http://plainpass.com/2013/11/asap-stores-passwords-in-plaintext.html' title='「ASAP 閃電購物網」密碼沒加密？ [更新]'/><author><name>Allen Own</name><uri>http://www.blogger.com/profile/07432128723498860159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgOTtJR54trZACfSZ1S-GfX8dHsYH3aLjRW6yUlr-mhSJ5cHFa2f0iPvaOYEB_AGShQpwl0tFbllzbdVooCPAh2wXx0OaEUOP6mdEB5n-yOUmnDwJC4LQ2gHlp7I4Z4Lk/s220/A2.png'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhBzPSc9INC70CDnM9n_Mnz0fjvYnfr-zOrQ5SMYd2wEVGX6TQuagrxvKYNGNUJmjGB01TDdiKW2NaDrWKMSXZciR8VI8rif-cNSvnRBqPVHyJCMwpD2eeLQIoI1m6LlKp2IIFkkcDKsFk/s72-c/ASAP_01.jpg" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4521309719030850665.post-5618182058016112720</id><published>2013-11-07T21:49:00.000+08:00</published><updated>2013-11-11T16:02:27.676+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Edu"/><category scheme="http://www.blogger.com/atom/ns#" term="PlainPass"/><category scheme="http://www.blogger.com/atom/ns#" term="Taiwan"/><title type='text'>「國立台灣科技大學碩博士班甄試招生」密碼沒加密！</title><content type='html'>昨天貼了「&lt;a href=&quot;http://plainpass.com/2013/11/nthu-adms-stores-passwords-plaintext.html&quot; target=&quot;_blank&quot;&gt;國立清華大學招生系統密碼沒加密&lt;/a&gt;」之後，馬上有人貼給我一堆學校。&lt;br /&gt;
看來學校真的是「兵家」必爭之地啊。:P&lt;br /&gt;
&lt;br /&gt;
感謝 Takeshi 的投稿！今天要看的是「國立台灣科技大學」，一樣是招生系統。&lt;br /&gt;
因為報名時間已過，我們直接拿 Takeshi 的截圖來說明。&lt;br /&gt;
&lt;br /&gt;
首先，報名已經先註冊好帳號了。接著忘記密碼...&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjzp3AugU9uaIFHBgFdvckx5FkkEwAlKjbV7UNL8WxN18dPaAU8C5gOOM0t0KdzLqixpXkxQ-OZbn-7zAHWjEVAAucxvUszoK0xuy89MgavWKn3uhcOrMY7zVmjS0nYRb_rmS82O4ea3bU/s1600/ntust-1.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;296&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjzp3AugU9uaIFHBgFdvckx5FkkEwAlKjbV7UNL8WxN18dPaAU8C5gOOM0t0KdzLqixpXkxQ-OZbn-7zAHWjEVAAucxvUszoK0xuy89MgavWKn3uhcOrMY7zVmjS0nYRb_rmS82O4ea3bU/s640/ntust-1.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
輸入身分證字號&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEik9RHIXfwciz4PFSGouia4RQvA7oLzUglam1SkiocsHJmqb1y0FLcLvxoaWZJg8kwMjMJ7QTm924pWuixVA_0vmy21llHp51Fq0Vfu6BFFe3n0h_y1xToUHKG-231zQPgpfHEpTVTqpXo/s1600/ntust-2.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;288&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEik9RHIXfwciz4PFSGouia4RQvA7oLzUglam1SkiocsHJmqb1y0FLcLvxoaWZJg8kwMjMJ7QTm924pWuixVA_0vmy21llHp51Fq0Vfu6BFFe3n0h_y1xToUHKG-231zQPgpfHEpTVTqpXo/s640/ntust-2.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
系統提示「請至 xxxx@gmail.com 收信取得密碼！」&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg5U9BQhEf_9cbQoRbaSEvCOLe0Zz8jmqrwO0-aKxpcLdY09mUFqifE7ktpgDNFzm0zuibOfZcnw2VHF8HSxeDbEwGMA4FAyxKRcPF-bnfeuDnozFD6EU7XQdfnQ2wdGP1w1cTejhvhqjI/s1600/ntust-3.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;284&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg5U9BQhEf_9cbQoRbaSEvCOLe0Zz8jmqrwO0-aKxpcLdY09mUFqifE7ktpgDNFzm0zuibOfZcnw2VHF8HSxeDbEwGMA4FAyxKRcPF-bnfeuDnozFD6EU7XQdfnQ2wdGP1w1cTejhvhqjI/s640/ntust-3.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
就收到你的密碼啦&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgmArUed80eDRgMxD1i4j1-c9XUnX58F7sV_Yf1Hxam0MRr73sdBTQUaDGRAMC4WAogBJ1IsQpSohKIZQnzLdowPtpHe743b0fuXWQezxNG4qgNymuqjyu5ePRcx_6dh0wnbAN_pASjMtw/s1600/ntust-4.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgmArUed80eDRgMxD1i4j1-c9XUnX58F7sV_Yf1Hxam0MRr73sdBTQUaDGRAMC4WAogBJ1IsQpSohKIZQnzLdowPtpHe743b0fuXWQezxNG4qgNymuqjyu5ePRcx_6dh0wnbAN_pASjMtw/s1600/ntust-4.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
很遺憾的，台科大也沒使用不可逆演算法儲存密碼。&lt;br /&gt;
希望大家多用正確的密碼機制囉！&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;「國立台灣科技大學碩博士班甄試招生」密碼沒加密！&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
日期：2013-11-08&lt;br /&gt;
名稱：國立台灣科技大學碩博士班甄試招生&lt;br /&gt;
網址：&lt;a href=&quot;https://entry.ntust.edu.tw/03entry1/login.aspx&quot;&gt;https://entry.ntust.edu.tw/03entry1/login.aspx&lt;/a&gt;&lt;br /&gt;
結果：密碼沒加密
&lt;br /&gt;
&lt;br /&gt;
感謝 Takeshi 的爆料！</content><link rel='replies' type='application/atom+xml' href='http://plainpass.com/feeds/5618182058016112720/comments/default' title='張貼留言'/><link rel='replies' type='text/html' href='http://plainpass.com/2013/11/ntust-stores-passwords-in-plaintext.html#comment-form' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/5618182058016112720'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/5618182058016112720'/><link rel='alternate' type='text/html' href='http://plainpass.com/2013/11/ntust-stores-passwords-in-plaintext.html' title='「國立台灣科技大學碩博士班甄試招生」密碼沒加密！'/><author><name>Allen Own</name><uri>http://www.blogger.com/profile/07432128723498860159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgOTtJR54trZACfSZ1S-GfX8dHsYH3aLjRW6yUlr-mhSJ5cHFa2f0iPvaOYEB_AGShQpwl0tFbllzbdVooCPAh2wXx0OaEUOP6mdEB5n-yOUmnDwJC4LQ2gHlp7I4Z4Lk/s220/A2.png'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjzp3AugU9uaIFHBgFdvckx5FkkEwAlKjbV7UNL8WxN18dPaAU8C5gOOM0t0KdzLqixpXkxQ-OZbn-7zAHWjEVAAucxvUszoK0xuy89MgavWKn3uhcOrMY7zVmjS0nYRb_rmS82O4ea3bU/s72-c/ntust-1.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4521309719030850665.post-8648571592814979967</id><published>2013-11-07T12:08:00.001+08:00</published><updated>2013-11-07T12:08:09.642+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Edu"/><category scheme="http://www.blogger.com/atom/ns#" term="PlainPass"/><category scheme="http://www.blogger.com/atom/ns#" term="Taiwan"/><title type='text'>「國立清華大學招生系統」密碼沒加密！</title><content type='html'>感謝 Anonymous 氣憤的爆料：「&lt;a href=&quot;https://www.ccxp.nthu.edu.tw/ccxp/adms/index.php&quot; target=&quot;_blank&quot;&gt;國立清華大學招生系統&lt;/a&gt;」的密碼竟然沒加密！&lt;br /&gt;
&lt;br /&gt;
但可惜目前不在招生期間，無法登入測試。因此僅提供螢幕截圖瞻仰一下。&lt;br /&gt;
根據 Anonymous 爆料指出，該招生系統問題不少。與學校溝通過，但成效不彰。&lt;br /&gt;
&lt;br /&gt;
讓我們來看看以下畫面：&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgtCDlcQuwBgGbkI3_d55l8cMB9a4caxcK5vX6D-uzrWhyokSzMs-BytLywoQnIAnQUOPf5WZh9M833dc4U4yJLIYlTL55w4VSK9ohCrmeYj4mlQYPf3_6Df_MRWuCsE_PjmnuyY_fVF-4/s1600/cc.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;630&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgtCDlcQuwBgGbkI3_d55l8cMB9a4caxcK5vX6D-uzrWhyokSzMs-BytLywoQnIAnQUOPf5WZh9M833dc4U4yJLIYlTL55w4VSK9ohCrmeYj4mlQYPf3_6Df_MRWuCsE_PjmnuyY_fVF-4/s640/cc.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
「考生修改密碼」的功能，竟然僅用 JavaScript 來比對密碼是否相同？我們都知道，在瀏覽器端（Client Side）的任何防禦，都只是防君子不防小人，頂多讓網頁的機制正確，但是毫無安全性。更何況使用 JavaScript 來驗證兩次密碼是否輸入正確，讓人不經想要嘗試直接關閉 JavaScript 後輸入看會發生什麼事情...&lt;br /&gt;
&lt;br /&gt;
再者，原始的密碼「O_PASSWORD」竟然直接寫在 hidden input 中進行比對... 令人懷疑資料庫中是否都直接存著所有報名學生的密碼？&lt;br /&gt;
&lt;br /&gt;
學校單位一直都是駭客眼中的肥羊：站台多、管理者少、頻寬大、漏洞多，還有滿滿的個資。希望學校單位能夠多注重資訊安全！&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;「國立清華大學招生系統」密碼沒加密！&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
日期：2013-11-07&lt;br /&gt;
名稱：國立清華大學招生系統&lt;br /&gt;
網址：&lt;a href=&quot;https://www.ccxp.nthu.edu.tw/ccxp/adms/index.php&quot;&gt;https://www.ccxp.nthu.edu.tw/ccxp/adms/index.php&lt;/a&gt;&lt;br /&gt;
結果：密碼沒加密
&lt;br /&gt;
&lt;br /&gt;</content><link rel='replies' type='application/atom+xml' href='http://plainpass.com/feeds/8648571592814979967/comments/default' title='張貼留言'/><link rel='replies' type='text/html' href='http://plainpass.com/2013/11/nthu-adms-stores-passwords-plaintext.html#comment-form' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/8648571592814979967'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/8648571592814979967'/><link rel='alternate' type='text/html' href='http://plainpass.com/2013/11/nthu-adms-stores-passwords-plaintext.html' title='「國立清華大學招生系統」密碼沒加密！'/><author><name>Allen Own</name><uri>http://www.blogger.com/profile/07432128723498860159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgOTtJR54trZACfSZ1S-GfX8dHsYH3aLjRW6yUlr-mhSJ5cHFa2f0iPvaOYEB_AGShQpwl0tFbllzbdVooCPAh2wXx0OaEUOP6mdEB5n-yOUmnDwJC4LQ2gHlp7I4Z4Lk/s220/A2.png'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgtCDlcQuwBgGbkI3_d55l8cMB9a4caxcK5vX6D-uzrWhyokSzMs-BytLywoQnIAnQUOPf5WZh9M833dc4U4yJLIYlTL55w4VSK9ohCrmeYj4mlQYPf3_6Df_MRWuCsE_PjmnuyY_fVF-4/s72-c/cc.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4521309719030850665.post-4392618496254440105</id><published>2013-11-05T11:52:00.000+08:00</published><updated>2013-11-05T11:52:04.497+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Submission"/><category scheme="http://www.blogger.com/atom/ns#" term="Taiwan"/><category scheme="http://www.blogger.com/atom/ns#" term="Telecom"/><title type='text'>「中華電信如意卡」密碼沒加密！</title><content type='html'>感謝&amp;nbsp;mousems 的投稿，本文轉載自 mousems&#39;s blog：「&lt;a href=&quot;http://mousems-blog.logdown.com/posts/158009-chunghwa-telecom-card-password-not-encrypted&quot;&gt;中華電信如意卡 密碼沒加密！&lt;/a&gt;」&lt;br /&gt;
&lt;br /&gt;
---&lt;br /&gt;
&lt;br /&gt;
今天登場的是中華電信如意卡&lt;br /&gt;
&lt;br /&gt;
站名：中華電信如意卡&lt;br /&gt;
網址：&lt;a href=&quot;https://www.telecity.com.tw/&quot;&gt;https://www.telecity.com.tw&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
這是首頁&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgtRrKm4Huvp03_1Ssp2hGgBsdu7yVleogNO0-BOqWUnxNdha5Ry1AttowvgLpvqQT6HEH5EzSqBA1UAsLn4ir7UDles98Sc0d9q1iXAmVaxHiHIkVPL5GVbCbLM4eTRmbAGORcgN-Z7Kc/s1600/Screen+Shot+2013-11-04+at+11.39.18+AM.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgtRrKm4Huvp03_1Ssp2hGgBsdu7yVleogNO0-BOqWUnxNdha5Ry1AttowvgLpvqQT6HEH5EzSqBA1UAsLn4ir7UDles98Sc0d9q1iXAmVaxHiHIkVPL5GVbCbLM4eTRmbAGORcgN-Z7Kc/s640/Screen+Shot+2013-11-04+at+11.39.18+AM.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
沒加密先生今天要從網站上面加值預付卡，當然要先註冊帳號囉&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEglGT1-WPp987-ufk_AoXf65S9lDze9Wdjjsc5vUDie2bcpTT2Jr1CRNSPQ1-1Xblt5XKb-t817EnuF1VzqnXBNF5Z600c0tZPGP0nywk-LRTsDS5b4YHy-UZB1LMdEtBqpQ-N0EdI6neA/s1600/Screen+Shot+2013-11-04+at+11.39.26+AM.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEglGT1-WPp987-ufk_AoXf65S9lDze9Wdjjsc5vUDie2bcpTT2Jr1CRNSPQ1-1Xblt5XKb-t817EnuF1VzqnXBNF5Z600c0tZPGP0nywk-LRTsDS5b4YHy-UZB1LMdEtBqpQ-N0EdI6neA/s640/Screen+Shot+2013-11-04+at+11.39.26+AM.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
要填寫的資料還滿多的，沒加密先生耐心的填寫完畢&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgOLybTFz20jlZxlN0iHnxApcAKQWx5Z4l2OC9vHrAXl_Xi8r8tbb6mfPpaEeCAwvvqlpBVp2BOQ41uACcxz8nySKYQV17GusofDX9FPI6jN6vbi45eycUx037bGOZ91sMPp0pMVuQrmmg/s1600/Screen+Shot+2013-11-04+at+11.43.59+AM.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgOLybTFz20jlZxlN0iHnxApcAKQWx5Z4l2OC9vHrAXl_Xi8r8tbb6mfPpaEeCAwvvqlpBVp2BOQ41uACcxz8nySKYQV17GusofDX9FPI6jN6vbi45eycUx037bGOZ91sMPp0pMVuQrmmg/s640/Screen+Shot+2013-11-04+at+11.43.59+AM.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
然後要驗證電子信箱&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhbDnoEvQtBmnqAsl-c1dz51CzM3vElEFCLhMTyNUSwqBVLZW5L2hGJdHi1HtA4LGq9WqkrapKtDnOXAz1uVu6t-ky-2XdBdZLIeXFfe-eGd9M94z7LjC6orMU_k87ypMHLouzNnRtHvP4/s1600/Screen+Shot+2013-11-04+at+11.44.30+AM.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhbDnoEvQtBmnqAsl-c1dz51CzM3vElEFCLhMTyNUSwqBVLZW5L2hGJdHi1HtA4LGq9WqkrapKtDnOXAz1uVu6t-ky-2XdBdZLIeXFfe-eGd9M94z7LjC6orMU_k87ypMHLouzNnRtHvP4/s640/Screen+Shot+2013-11-04+at+11.44.30+AM.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
驗證信很貼心的提醒剛剛輸入的密碼&lt;br /&gt;
不過這不能證明沒加密先生的密碼沒加密&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhA2FhB9u17va4rmfmLOhKgMQtcOSDYjDHIpahvxX4afGuEozL-2PLXCrgHMWrKOtGvYXZBs-Wm4TAYMs5V6XpOMg6Rc0QjMERn-v544xPto7T6eJAQaZwGbYqPYvG_vwhBK2mrw5mYjus/s1600/Screen+Shot+2013-11-04+at+11.45.17+AM.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhA2FhB9u17va4rmfmLOhKgMQtcOSDYjDHIpahvxX4afGuEozL-2PLXCrgHMWrKOtGvYXZBs-Wm4TAYMs5V6XpOMg6Rc0QjMERn-v544xPto7T6eJAQaZwGbYqPYvG_vwhBK2mrw5mYjus/s640/Screen+Shot+2013-11-04+at+11.45.17+AM.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
驗證成功的頁面也很貼心的提醒密碼
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgQrO3xn-YhYfKWMb_ky3Y_3aBXopNgcOEmOLWaCc35bLNTjXW6L-6X0lmo54QDxUlAFwWi9AV9Sy8Pl3MBR83x3ItfA_V3-BBaLey-eixEUp_XpNGV2pKILFaagnuQ3IaigmJfr4R2E0k/s1600/Screen+Shot+2013-11-04+at+11.45.28+AM.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgQrO3xn-YhYfKWMb_ky3Y_3aBXopNgcOEmOLWaCc35bLNTjXW6L-6X0lmo54QDxUlAFwWi9AV9Sy8Pl3MBR83x3ItfA_V3-BBaLey-eixEUp_XpNGV2pKILFaagnuQ3IaigmJfr4R2E0k/s640/Screen+Shot+2013-11-04+at+11.45.28+AM.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
提醒了這麼多次，你也知道的，沒加密先生的記憶力相當差，所以他在十秒後就忘記密碼了...&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiueju16SpepfdNBjg_s-nWxhNS6EaRzl4hysW07HDAUVw9UBUfGrSGRopt9b7KvutjMPiynxT8Qrv8jFPIpOTxC8Fic_vhdK9oqEQA9iLQ0TM44a7OB61E_JwW0iHu8lfb2W-mcI21sCs/s1600/Screen+Shot+2013-11-04+at+11.45.50+AM.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiueju16SpepfdNBjg_s-nWxhNS6EaRzl4hysW07HDAUVw9UBUfGrSGRopt9b7KvutjMPiynxT8Qrv8jFPIpOTxC8Fic_vhdK9oqEQA9iLQ0TM44a7OB61E_JwW0iHu8lfb2W-mcI21sCs/s640/Screen+Shot+2013-11-04+at+11.45.50+AM.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
跳出的提示窗好像透露了什麼訊息&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiZhay9lI2oTmulv7NnNQTOPaVf_gAnOHY32ao7bNr1FnTlnU7HO2hM9yvRg0lwpV3Sc9GE4ORxaS_8tU0izH7dzcUtpFP5IlBpHgcklfwkTdVOQdgmuAx8AOaYoKYqi8MTGzuGhVeuwug/s1600/Screen+Shot+2013-11-04+at+11.45.57+AM.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiZhay9lI2oTmulv7NnNQTOPaVf_gAnOHY32ao7bNr1FnTlnU7HO2hM9yvRg0lwpV3Sc9GE4ORxaS_8tU0izH7dzcUtpFP5IlBpHgcklfwkTdVOQdgmuAx8AOaYoKYqi8MTGzuGhVeuwug/s640/Screen+Shot+2013-11-04+at+11.45.57+AM.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
打開信箱後，密碼沒寄來，倒是發現野生的50元折價券，冥冥之中好像告訴沒加密先生不要投稿&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgZoWDpzkwBfwedCPplE-sNyAfSTVApgzvWNvOw1JgrHnhDSbnbq6Gxygg7GeI33fwTedVqTfMsZYXm4vTutU6MGMNRapyoUWUJuqlT9iAhpckzjVA1FJcVJJz8pJOy91HRLqRZ2VlPBXA/s1600/Screen+Shot+2013-11-04+at+11.46.43+AM.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgZoWDpzkwBfwedCPplE-sNyAfSTVApgzvWNvOw1JgrHnhDSbnbq6Gxygg7GeI33fwTedVqTfMsZYXm4vTutU6MGMNRapyoUWUJuqlT9iAhpckzjVA1FJcVJJz8pJOy91HRLqRZ2VlPBXA/s640/Screen+Shot+2013-11-04+at+11.46.43+AM.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
既然沒收到信，沒加密先生回去逛逛了修改資料的頁面，發現...其實剛剛根本不用按忘記密碼嘛&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi_6LfDen3DldLVJa1rIF9lxZ2ZOAA3E-2xfSnBEDAPi48Nm_tl_UUUTdzRCHOA2A7nVC6lUgmEme8_WO2otRi4ZSpwbvyxOqNxZtKat4CnvJ4EDZkr6XkPd2AR0Y8vMIcvEDRfddlKvFU/s1600/Screen+Shot+2013-11-04+at+11.49.02+AM.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi_6LfDen3DldLVJa1rIF9lxZ2ZOAA3E-2xfSnBEDAPi48Nm_tl_UUUTdzRCHOA2A7nVC6lUgmEme8_WO2otRi4ZSpwbvyxOqNxZtKat4CnvJ4EDZkr6XkPd2AR0Y8vMIcvEDRfddlKvFU/s640/Screen+Shot+2013-11-04+at+11.49.02+AM.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
過了幾分鐘信終於來了，想當然密碼是沒加密。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh9DMIVeBLPXzBDnhwvXi-iB0QMkiQmK6Eisenim3rTi2TzKSX2RzNlWJpePqVHI_SgPH0Jsre2eTTxdSB5A9Kezc8wbZttaz9UnTld-RaPhLWNAhv0mzdaHhafv1P37YxgHSmxQs0L2d4/s1600/Screen+Shot+2013-11-04+at+11.49.43+AM.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh9DMIVeBLPXzBDnhwvXi-iB0QMkiQmK6Eisenim3rTi2TzKSX2RzNlWJpePqVHI_SgPH0Jsre2eTTxdSB5A9Kezc8wbZttaz9UnTld-RaPhLWNAhv0mzdaHhafv1P37YxgHSmxQs0L2d4/s640/Screen+Shot+2013-11-04+at+11.49.43+AM.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
日期：2013-11-04&lt;br /&gt;
名稱：中華電信如意卡&lt;br /&gt;
網址：&lt;a href=&quot;https://www.telecity.com.tw/&quot;&gt;https://www.telecity.com.tw&lt;/a&gt;&lt;br /&gt;
結果：密碼沒加密&lt;br /&gt;
&lt;a href=&quot;http://draft.blogger.com/&quot;&gt;&lt;/a&gt;&lt;span id=&quot;goog_19103187&quot;&gt;&lt;/span&gt;&lt;span id=&quot;goog_19103188&quot;&gt;&lt;/span&gt;&lt;br /&gt;</content><link rel='replies' type='application/atom+xml' href='http://plainpass.com/feeds/4392618496254440105/comments/default' title='張貼留言'/><link rel='replies' type='text/html' href='http://plainpass.com/2013/11/telecity-stores-passwords-in-plaintext.html#comment-form' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/4392618496254440105'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/4392618496254440105'/><link rel='alternate' type='text/html' href='http://plainpass.com/2013/11/telecity-stores-passwords-in-plaintext.html' title='「中華電信如意卡」密碼沒加密！'/><author><name>Allen Own</name><uri>http://www.blogger.com/profile/07432128723498860159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgOTtJR54trZACfSZ1S-GfX8dHsYH3aLjRW6yUlr-mhSJ5cHFa2f0iPvaOYEB_AGShQpwl0tFbllzbdVooCPAh2wXx0OaEUOP6mdEB5n-yOUmnDwJC4LQ2gHlp7I4Z4Lk/s220/A2.png'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgtRrKm4Huvp03_1Ssp2hGgBsdu7yVleogNO0-BOqWUnxNdha5Ry1AttowvgLpvqQT6HEH5EzSqBA1UAsLn4ir7UDles98Sc0d9q1iXAmVaxHiHIkVPL5GVbCbLM4eTRmbAGORcgN-Z7Kc/s72-c/Screen+Shot+2013-11-04+at+11.39.18+AM.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4521309719030850665.post-6290814074518730483</id><published>2013-11-04T10:52:00.000+08:00</published><updated>2013-11-04T12:38:20.844+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="PlainPass"/><category scheme="http://www.blogger.com/atom/ns#" term="Shopping"/><category scheme="http://www.blogger.com/atom/ns#" term="Taiwan"/><title type='text'>「uitox - igarden 網路商店」密碼沒加密！</title><content type='html'>「&lt;a href=&quot;http://instant.uitox.com/&quot; target=&quot;_blank&quot;&gt;igarden 網路商店&lt;/a&gt;」是由「&lt;a href=&quot;http://www.uitox.com/&quot; target=&quot;_blank&quot;&gt;uitox 全球電子商務集團&lt;/a&gt;」所推出的開店平台：&lt;br /&gt;
&lt;blockquote class=&quot;tr_bq&quot;&gt;
全新網路開店平台，由 uitox 電子商務集團在台灣建立。提供您10分鐘開店，台北市6小時到貨，全台灣24小時到貨（簽約後），最迅速的開店服務！&lt;/blockquote&gt;
&lt;div&gt;
非常有潛力以及野心的電子商務平台，也有不少的新聞報導：「&lt;a href=&quot;http://www.appledaily.com.tw/appledaily/article/finance/20131101/35406384/PChome%E5%89%8D%E7%87%9F%E9%81%8B%E9%95%B7%E6%93%8D%E5%88%80%E8%B3%BC%E7%89%A9%E5%B9%B3%E5%8F%B0uitox%E6%88%90%E8%BB%8D&quot; target=&quot;_blank&quot;&gt;PChome前營運長操刀 購物平台uitox成軍&lt;/a&gt;」，在創業圈、電子商務圈聲勢非常浩大。&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
但是日前經由網友爆料，uitox 所推出的開店平台密碼竟然沒加密？&lt;/div&gt;
&lt;div&gt;
這在一個新創網站實在不是一個好現象。讓我們來試看看...&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiU6E3Pc7qFxmspXQ5YyOid7seq3OcR-MVZGzeDcrR_-w12uG1iZw4fIjYyapTdlEcKUVUFBS8NSea7mvdlAc8WM8nAMVKPSA2Ms5DAYU5Q_yr3xrOVxEiWsfJJiX4zvxsDrdt6gIRbMeg/s1600/igarden_01.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;394&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiU6E3Pc7qFxmspXQ5YyOid7seq3OcR-MVZGzeDcrR_-w12uG1iZw4fIjYyapTdlEcKUVUFBS8NSea7mvdlAc8WM8nAMVKPSA2Ms5DAYU5Q_yr3xrOVxEiWsfJJiX4zvxsDrdt6gIRbMeg/s640/igarden_01.jpg&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
首先註冊實在是太方便了，不管你是用 Facebook 還是直接輸入 Email 跟密碼都可以。&lt;br /&gt;
不需要囉嗦的輸入什麼個人資料...&lt;br /&gt;
&lt;br /&gt;
但是網站上並沒有任何有關個資以及資訊安全相關的使用說明，實在令人有點不放心啊。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgFyd_JTwIAvP81EG3bA0t40T3KcL4-ORtvMig6OroxRMJdq6Ly_Rn6DAbtZkU8_pDe4FWiI94q-SDe5e-q58hTCfPuc0rtnb0HSJ_5dA68NzK-tEO9u5TcqYq3Q25NqFB0yRZfrewVmuU/s1600/igarden_02.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;394&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgFyd_JTwIAvP81EG3bA0t40T3KcL4-ORtvMig6OroxRMJdq6Ly_Rn6DAbtZkU8_pDe4FWiI94q-SDe5e-q58hTCfPuc0rtnb0HSJ_5dA68NzK-tEO9u5TcqYq3Q25NqFB0yRZfrewVmuU/s640/igarden_02.jpg&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
直接就註冊完成了！&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjI__3aQ5yYJjeW3dvm0gPpqrXxghPMkENLjiVXAThs74bXT7Is9o0YDqY1zh4avb9BR_60L8K02S4qvbuGAWX6UZyWSHC0QrZC-qm9H60O79HlKYLTl04CV68_9pSiDiCGZwRdlEXqFho/s1600/igarden_03.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;394&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjI__3aQ5yYJjeW3dvm0gPpqrXxghPMkENLjiVXAThs74bXT7Is9o0YDqY1zh4avb9BR_60L8K02S4qvbuGAWX6UZyWSHC0QrZC-qm9H60O79HlKYLTl04CV68_9pSiDiCGZwRdlEXqFho/s640/igarden_03.jpg&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
直接從首頁點選忘記密碼...&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjFHxrqcM3pgRezvkEVueTWzBOMe6FeZvx3YNFRTSAM9codsu1UbC1NolqtPwA1gshGYCAmYTvaiHjhLCRTMcDJH8whZG08VMdTJtQNKn5cXGYS6a4ZC0aAkp7a25u9R0fYPn3tehXE-es/s1600/igarden_04.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;394&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjFHxrqcM3pgRezvkEVueTWzBOMe6FeZvx3YNFRTSAM9codsu1UbC1NolqtPwA1gshGYCAmYTvaiHjhLCRTMcDJH8whZG08VMdTJtQNKn5cXGYS6a4ZC0aAkp7a25u9R0fYPn3tehXE-es/s640/igarden_04.jpg&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
很乾脆的說「密碼已發送至您所填的 email」！&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhS6m8GIu6h8pkavoJAQk7RN1Q5S8tg7Bfeqdz1C_NbPevKyhWWqMhuh-z3HQjj3R30AM4qRjPGvXNYJpNokCfP3igkLtL3No93MOoCUpmrig1lCO3q5ojOVF0RO8iEOsMw66Ggwr5lM-c/s1600/igarden_05.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhS6m8GIu6h8pkavoJAQk7RN1Q5S8tg7Bfeqdz1C_NbPevKyhWWqMhuh-z3HQjj3R30AM4qRjPGvXNYJpNokCfP3igkLtL3No93MOoCUpmrig1lCO3q5ojOVF0RO8iEOsMw66Ggwr5lM-c/s1600/igarden_05.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
我們也很乾脆的收到了原本的密碼「plainpass」，不囉嗦！&lt;br /&gt;
這應該也是一種便民？&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiYFICGiSYdMswkGF2FnAbAuLEv3DbHa1pYJR0aS9FeT2konFmsz-2CFucLDOzCeIzhCIE540KYPxJdnn3iGWd6mkhWbzTEEKrRTCwbhXYel7j1Dc6dNOhYSNkt6yccsozHZzLCdpXuID4/s1600/igarden_06.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;414&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiYFICGiSYdMswkGF2FnAbAuLEv3DbHa1pYJR0aS9FeT2konFmsz-2CFucLDOzCeIzhCIE540KYPxJdnn3iGWd6mkhWbzTEEKrRTCwbhXYel7j1Dc6dNOhYSNkt6yccsozHZzLCdpXuID4/s640/igarden_06.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
網友的爆料截圖也證明了這一點，只是當時的名字還是「uitox 雲商店」&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg4cQg5YqzEfrtHWwFxqcKWtSecfmEmaFz49xZ58KAaM1nqVaq5GXsTYTMt3SQlB9hXC9CIgiCbNwUjb62AS17OO_1Vmbo6pG5mb-F2dhWPMM0PTwoY2hTQ8aN8J-0LFf2HO6RNnbAaHR0/s1600/igarden_07.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;286&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg4cQg5YqzEfrtHWwFxqcKWtSecfmEmaFz49xZ58KAaM1nqVaq5GXsTYTMt3SQlB9hXC9CIgiCbNwUjb62AS17OO_1Vmbo6pG5mb-F2dhWPMM0PTwoY2hTQ8aN8J-0LFf2HO6RNnbAaHR0/s640/igarden_07.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div&gt;
&lt;span style=&quot;color: red;&quot;&gt;附帶抱怨一下，測試完畢後我本來想改個密碼，但是卻發現本站完全沒有修改個人資料或者密碼的地方...&amp;nbsp;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
身為新創企業，又是電子商務平台，更必須要注意資訊安全啊！&lt;/div&gt;
&lt;div&gt;
資安的議題非常重要，也嚴重的影響了電子商務的運作。&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
可以參考資安人的這篇文章：&lt;a href=&quot;http://www.informationsecurity.com.tw/article/article_detail.aspx?tv=71&amp;amp;aid=7649&quot; target=&quot;_blank&quot;&gt;行動上網人口已逾4成 資安因素阻礙網路購物、網路金融&lt;/a&gt;&lt;/div&gt;
&lt;div&gt;
&lt;blockquote class=&quot;tr_bq&quot;&gt;
然而根據調查指出，74%民眾在上網時最擔心個資外洩，並且有68.8%的上網民眾因為「網站要求輸入個人資料而放棄使用上網服務」的經驗，同時也因考量資訊安全因素，而減少使用網路購物、網路金融服務、網路社群、以及需登入個資的服務。&lt;/blockquote&gt;
&lt;div&gt;
希望大家能夠多注重資安啊！&lt;/div&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;「igarden 網路商店」密碼沒加密！&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
日期：2013-11-04&lt;br /&gt;
名稱：uitox - igarden 網路商店&lt;br /&gt;
網址：&lt;a href=&quot;http://instant.uitox.com/&quot;&gt;http://instant.uitox.com&lt;/a&gt;&lt;br /&gt;
結果：密碼沒加密
&lt;br /&gt;
&lt;br /&gt;
感謝 appleboy 的爆料！</content><link rel='replies' type='application/atom+xml' href='http://plainpass.com/feeds/6290814074518730483/comments/default' title='張貼留言'/><link rel='replies' type='text/html' href='http://plainpass.com/2013/11/uitox-igarden-stores-passwords-in-plaintext.html#comment-form' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/6290814074518730483'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/6290814074518730483'/><link rel='alternate' type='text/html' href='http://plainpass.com/2013/11/uitox-igarden-stores-passwords-in-plaintext.html' title='「uitox - igarden 網路商店」密碼沒加密！'/><author><name>Allen Own</name><uri>http://www.blogger.com/profile/07432128723498860159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgOTtJR54trZACfSZ1S-GfX8dHsYH3aLjRW6yUlr-mhSJ5cHFa2f0iPvaOYEB_AGShQpwl0tFbllzbdVooCPAh2wXx0OaEUOP6mdEB5n-yOUmnDwJC4LQ2gHlp7I4Z4Lk/s220/A2.png'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiU6E3Pc7qFxmspXQ5YyOid7seq3OcR-MVZGzeDcrR_-w12uG1iZw4fIjYyapTdlEcKUVUFBS8NSea7mvdlAc8WM8nAMVKPSA2Ms5DAYU5Q_yr3xrOVxEiWsfJJiX4zvxsDrdt6gIRbMeg/s72-c/igarden_01.jpg" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4521309719030850665.post-3424909189977760010</id><published>2013-10-21T14:00:00.000+08:00</published><updated>2013-10-21T14:00:36.602+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="PlainPass"/><category scheme="http://www.blogger.com/atom/ns#" term="Taiwan"/><category scheme="http://www.blogger.com/atom/ns#" term="Ticket"/><category scheme="http://www.blogger.com/atom/ns#" term="Travel"/><title type='text'>「長榮航空 EVA AIR」密碼沒加密！</title><content type='html'>「&lt;a href=&quot;http://www.evaair.com/&quot; target=&quot;_blank&quot;&gt;長榮航空&amp;nbsp;EVA AIR&lt;/a&gt;」是台灣第二大民用航空業者，也是國際知名的航空。&lt;br /&gt;
&lt;br /&gt;
如同先前「&lt;a href=&quot;http://plainpass.com/search/label/Travel&quot; target=&quot;_blank&quot;&gt;旅遊系列&lt;/a&gt;」說寫的，這類型網站通常都提供線上訂票，並且有很多優惠。在出國的旺季這類型的網站使用率非常高。但是這些網站的資安做得怎樣呢？&lt;br /&gt;
&lt;br /&gt;
之前談到&lt;a href=&quot;http://plainpass.com/2013/09/china-airline-stores-passwords-in-plaintext.html&quot; target=&quot;_blank&quot;&gt;「中華航空」的密碼問題&lt;/a&gt;，今天我們來看看長榮航空。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg-WdSTbvEe0knoRzlVwOXTvc_XVYK7WUthBPrHovoaizh4jHP8h6LB1dWxiVuL_OZyN4LHh3vHSj7ulArjTi_4DXG1d9-M4D4fcchiskNr822j43XAflPE7GJ-6M13LnQzYAAzhYyQA3k/s1600/evaair_01.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;482&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg-WdSTbvEe0knoRzlVwOXTvc_XVYK7WUthBPrHovoaizh4jHP8h6LB1dWxiVuL_OZyN4LHh3vHSj7ulArjTi_4DXG1d9-M4D4fcchiskNr822j43XAflPE7GJ-6M13LnQzYAAzhYyQA3k/s640/evaair_01.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&amp;nbsp;首先我們來註冊一組帳號，註冊帳號需要填寫非常多個人資料，在註冊欄位中有寫非常多個人資料使用原則跟資安規則。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEii5EiEYALCI1r-Z2oRZ2g_sOKqHzhBZaLMJx9Owt4O2xxyRWWx7y-g8WReM-QYvZCFhv2ZL9_N9wugvVdB38bm7kO7MqxS2xxNUW5uB7ewFiRncxe83OWc6B_AOyh8MTL-snUmrmFnlPc/s1600/evaair_02.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;482&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEii5EiEYALCI1r-Z2oRZ2g_sOKqHzhBZaLMJx9Owt4O2xxyRWWx7y-g8WReM-QYvZCFhv2ZL9_N9wugvVdB38bm7kO7MqxS2xxNUW5uB7ewFiRncxe83OWc6B_AOyh8MTL-snUmrmFnlPc/s640/evaair_02.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
其中密碼設定原則大部分都寫得非常好，不要使用容易猜中的字母、出生年月日、電話等，也不要使用跟其他網路服務相同的密碼，不要外洩自己的密碼，這些都是我們一直提倡的重點。&lt;br /&gt;
&lt;br /&gt;
而密碼的長度竟然是「6-8個字元」，這實在是有點短，雖然有要求密碼的複雜度。&lt;br /&gt;
&lt;br /&gt;
另外有一點：&lt;br /&gt;
&lt;blockquote class=&quot;tr_bq&quot;&gt;
會員如發現本項服務遭第三人盜用，應立即通知本公司。但上述通知不得解釋為本公司對會員有任何形式之賠償或補償之責任或義務。&lt;/blockquote&gt;
這樣子好嗎？&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiu76dYNhLq3nEEqoJQye7RI0AwhuPM1-GxBFCwSIgNy7CRG0qarXl-ClJQ1R9RwHdr6GGqhgz0oQsBjMKkyYvZTKhICFyIvG7CLSJ9DMH2q8hqhLGs8RlPCw-EhgYG7fikfzrKyAakBuA/s1600/evaair_03.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;265&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiu76dYNhLq3nEEqoJQye7RI0AwhuPM1-GxBFCwSIgNy7CRG0qarXl-ClJQ1R9RwHdr6GGqhgz0oQsBjMKkyYvZTKhICFyIvG7CLSJ9DMH2q8hqhLGs8RlPCw-EhgYG7fikfzrKyAakBuA/s640/evaair_03.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
接著註冊帳號跟密碼，非常有趣。&lt;br /&gt;
&lt;br /&gt;
密碼的長度跟複雜度前面已經有說明了，「6-8個字元」、「需包含英文及數字，英文大小寫」。但是帳號竟然是「6-25個字元，需包含英文及數字」，為什麼有種帳號比密碼還要安全的感覺？&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgKJa-EMPvFIvDyI3MuLj1uhNzbG6RMf8VLZkau0RPHaWcn6dOQkJwci64cr2Jir9S9_B2-XQWOzUD-7DEvNXQRTQeJU-hcA8gh0xkN3JLNeK2qSE0qz8Yn0UUVzk3esdLIWBj9fAmC1gw/s1600/evaair_04.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;330&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgKJa-EMPvFIvDyI3MuLj1uhNzbG6RMf8VLZkau0RPHaWcn6dOQkJwci64cr2Jir9S9_B2-XQWOzUD-7DEvNXQRTQeJU-hcA8gh0xkN3JLNeK2qSE0qz8Yn0UUVzk3esdLIWBj9fAmC1gw/s640/evaair_04.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
確認同意會員條款～&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj9AEm7-ICh1OCYbwUt7OEOjLC8pqQqR9ttL2xCUFXZVGkf4gXhbBdqiChDQ3JD03j9L8JaqQ1wLcBZkM83-yQG34HtcBAL2chwF7lFsf3eEJcMabQ3jj8fhKr2Q-RZuLEGdB-7dScA_eE/s1600/evaair_05.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;462&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj9AEm7-ICh1OCYbwUt7OEOjLC8pqQqR9ttL2xCUFXZVGkf4gXhbBdqiChDQ3JD03j9L8JaqQ1wLcBZkM83-yQG34HtcBAL2chwF7lFsf3eEJcMabQ3jj8fhKr2Q-RZuLEGdB-7dScA_eE/s640/evaair_05.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
途中發生不少插曲，包括突然發現系統維護中。今天是週末啊... 工程師真辛苦(?)。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhj34QOTdxZKQdEh_tVbRGYdmrHumVTW7N8HMU_xgrDxiZBvRhezjJDHzOWAwfqe-MMKTeqTbqAVSpryvkV9MHJ31OVWGqop3h_3lsYnYbeP0oFnEXp55mEN7WzSXhq29eJIWGB3f78Sw4/s1600/evaair_06.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;78&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhj34QOTdxZKQdEh_tVbRGYdmrHumVTW7N8HMU_xgrDxiZBvRhezjJDHzOWAwfqe-MMKTeqTbqAVSpryvkV9MHJ31OVWGqop3h_3lsYnYbeP0oFnEXp55mEN7WzSXhq29eJIWGB3f78Sw4/s640/evaair_06.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
註冊成功後，馬上回到首頁點選登入-&amp;gt;忘記密碼。但是其中密碼查詢需要卡號，所以我們先去查詢卡號。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhoPh3adr7sbqatWLItebWkYNkcZpuiba3h0IQUXOum6q4VoKIV81BXPwxJWVYKr9I_1SKeiyo8P7VjezJCM7U8IfUsdh3IAIzZXL6R2xKohr_PlQ4KA91kbOks1KJGMHZzjAFjcreh8S4/s1600/evaair_07.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;482&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhoPh3adr7sbqatWLItebWkYNkcZpuiba3h0IQUXOum6q4VoKIV81BXPwxJWVYKr9I_1SKeiyo8P7VjezJCM7U8IfUsdh3IAIzZXL6R2xKohr_PlQ4KA91kbOks1KJGMHZzjAFjcreh8S4/s640/evaair_07.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
查詢卡號需要國籍、身分證字號或護照號碼、生日。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhnWTdq88jA3P_8iI-Kase7KJBZLbtgqn2ZGYgBOIVY3PfsYHH_SVVH-EQYlwcgixbZw2UP77LnaqBwFA5OF5Vnw5Z8Q5A4o7xfoVN0CT3N_-vpFXmZ6b9rUFtLggEInc6g4nX9zI2Lfus/s1600/evaair_08.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;482&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhnWTdq88jA3P_8iI-Kase7KJBZLbtgqn2ZGYgBOIVY3PfsYHH_SVVH-EQYlwcgixbZw2UP77LnaqBwFA5OF5Vnw5Z8Q5A4o7xfoVN0CT3N_-vpFXmZ6b9rUFtLggEInc6g4nX9zI2Lfus/s640/evaair_08.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
來到密碼查詢了，輸入卡號、姓名、國籍、護照號碼、身分證號碼跟生日。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg0FOarOjvaUrt6B6ybsjVzAniN9ITkUsfZw87L7ch6ZIqROHS7gsMvbgp491E5gc1qcDjeA3mDbncTsgoyBdK2tRtFivdUMOQXYWVoM8YCiUXHkwJvcwxr5t-mO5jbZRmr0ysAfhWv0dc/s1600/evaair_09.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;482&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg0FOarOjvaUrt6B6ybsjVzAniN9ITkUsfZw87L7ch6ZIqROHS7gsMvbgp491E5gc1qcDjeA3mDbncTsgoyBdK2tRtFivdUMOQXYWVoM8YCiUXHkwJvcwxr5t-mO5jbZRmr0ysAfhWv0dc/s640/evaair_09.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
系統寄出郵件。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjXkdIknVcuUeyjpyMWwYS4Hi_2fkpixd8f85HUEH6ii8B8Q92OdtJfu31pIrLGUNkcpblsmhzjLTV6UjcyiRanMKpIhIQFZv8lWT-d_GcZ_Oj3FksMHmXNbe6tDi9C76hMF8susnRbjzs/s1600/evaair_10.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;482&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjXkdIknVcuUeyjpyMWwYS4Hi_2fkpixd8f85HUEH6ii8B8Q92OdtJfu31pIrLGUNkcpblsmhzjLTV6UjcyiRanMKpIhIQFZv8lWT-d_GcZ_Oj3FksMHmXNbe6tDi9C76hMF8susnRbjzs/s640/evaair_10.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
收到信件啦！的確為我們所設定的「八個字元」「英文大小寫數字混雜」密碼。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhGHqiStgLY9rAgqTLVKG8VFiB5WmxTJxnr3x4GEnVdsufnr_UwaI8tn7rUOh5A_UCUAy_NFTMNjwho_vBS6PIEmrUrGg7OlMkrK2XxVyY0Z_jLgfigmv-oCbqrjImQSOBRGLjZpz1hVK0/s1600/evaair_11.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;482&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhGHqiStgLY9rAgqTLVKG8VFiB5WmxTJxnr3x4GEnVdsufnr_UwaI8tn7rUOh5A_UCUAy_NFTMNjwho_vBS6PIEmrUrGg7OlMkrK2XxVyY0Z_jLgfigmv-oCbqrjImQSOBRGLjZpz1hVK0/s640/evaair_11.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
希望各大航空、旅遊網站都要把密碼的機制設計好，避免駭客盜取密碼的問題啊。&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;「長榮航空 EVA AIR」密碼沒加密！&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
日期：2013-10-19&lt;br /&gt;
名稱：長榮航空 EVA AIR&lt;br /&gt;
網址：&lt;a href=&quot;http://www.evaair.com/&quot;&gt;http://www.evaair.com/&lt;/a&gt;&lt;br /&gt;
結果：密碼沒加密
&lt;br /&gt;
&lt;br /&gt;</content><link rel='replies' type='application/atom+xml' href='http://plainpass.com/feeds/3424909189977760010/comments/default' title='張貼留言'/><link rel='replies' type='text/html' href='http://plainpass.com/2013/10/eva-air-stores-passwords-in-plaintext.html#comment-form' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/3424909189977760010'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/3424909189977760010'/><link rel='alternate' type='text/html' href='http://plainpass.com/2013/10/eva-air-stores-passwords-in-plaintext.html' title='「長榮航空 EVA AIR」密碼沒加密！'/><author><name>Allen Own</name><uri>http://www.blogger.com/profile/07432128723498860159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgOTtJR54trZACfSZ1S-GfX8dHsYH3aLjRW6yUlr-mhSJ5cHFa2f0iPvaOYEB_AGShQpwl0tFbllzbdVooCPAh2wXx0OaEUOP6mdEB5n-yOUmnDwJC4LQ2gHlp7I4Z4Lk/s220/A2.png'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg-WdSTbvEe0knoRzlVwOXTvc_XVYK7WUthBPrHovoaizh4jHP8h6LB1dWxiVuL_OZyN4LHh3vHSj7ulArjTi_4DXG1d9-M4D4fcchiskNr822j43XAflPE7GJ-6M13LnQzYAAzhYyQA3k/s72-c/evaair_01.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4521309719030850665.post-3085104136273060706</id><published>2013-10-19T16:31:00.000+08:00</published><updated>2013-10-19T16:31:04.718+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="PlainPass"/><category scheme="http://www.blogger.com/atom/ns#" term="Submission"/><category scheme="http://www.blogger.com/atom/ns#" term="Taiwan"/><category scheme="http://www.blogger.com/atom/ns#" term="Telecom"/><title type='text'>「威寶電信」密碼沒加密！</title><content type='html'>很難得寫電信公司系列，感謝 Anonymous 的投稿！&lt;br /&gt;
&lt;br /&gt;
「&lt;a href=&quot;http://www.vibo.com.tw/&quot; target=&quot;_blank&quot;&gt;威寶電信&lt;/a&gt;」是台灣知名電信商，我想就不用多介紹了。電信公司的網站提供非常多加值服務，資訊安全我想一定是非常重視的，畢竟裡面包含了非常多個資。&lt;br /&gt;
&lt;br /&gt;
今天就讓我們來看看吧！&lt;br /&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiVl6_5y3296TfRs-6V0hv_eo9BjT2_ZzZ8ajmkfOztVz6T2R6CFFtKWTEBZxJtrZ8qwTSuQ0CADepmhyfXpggqJJM7H8Q3Q_08mUTPg69TVXk34C_glqmhQiEb21KFVY2wM4CCEkWLaOM/s1600/vibo_01.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em; text-align: center;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;314&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiVl6_5y3296TfRs-6V0hv_eo9BjT2_ZzZ8ajmkfOztVz6T2R6CFFtKWTEBZxJtrZ8qwTSuQ0CADepmhyfXpggqJJM7H8Q3Q_08mUTPg69TVXk34C_glqmhQiEb21KFVY2wM4CCEkWLaOM/s640/vibo_01.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
在網站的&lt;a href=&quot;http://www.vibo.com.tw/CWS/private.html&quot; target=&quot;_blank&quot;&gt;隱私權聲明&lt;/a&gt;中，有幾點引述...&lt;br /&gt;
&lt;blockquote class=&quot;tr_bq&quot;&gt;
為了保護使用者個人資料之完整及安全，保存使用者個人資料之資料處理系統均已受妥善的維護，並符合相關主管機關嚴格之要求，以保障使用者的個人資料不會被不當取得或破壞。&amp;nbsp;&lt;/blockquote&gt;
嗯，很常見的聲明，只是有沒有好好的做保護就是另當別論了。&lt;br /&gt;
或許很多公司的安全跟我們資安圈所謂的安全不太一樣吧？&lt;br /&gt;
&lt;br /&gt;
但是另一段就很需要我們注意一下了。&lt;br /&gt;
&lt;blockquote class=&quot;tr_bq&quot;&gt;
用戶個人資料的使用與修改&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;使用者在本網站中可以隨時利用您個人申請的帳號和密碼，更改使用者所輸入的任何個人或公司資料。&lt;/span&gt;&lt;/b&gt;&lt;/blockquote&gt;
&lt;div&gt;
意思是，威寶可以拿我們的帳號跟密碼來「利用」？&lt;br /&gt;
雖然說在業務範圍拿來利用是正常，但是如果網站的密碼沒加密？&lt;br /&gt;
是否威寶就可以知道我們的密碼？&lt;br /&gt;
&lt;br /&gt;
讓我們馬上來看看。&lt;br /&gt;
&lt;br /&gt;
直接在網站上點選「忘記密碼」&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhPf_duawF3w6_tEqhCcWVHbJsqOzeL7IqaF1aeZyQbYX2iIcGJLYLNVmy_8bIFTWYcL73VSnofvqaIuaHEltVSBE4NMug4-rpEK3gXxiGmg3GL_suPsg2LZIFUGPnh7wtQrLjNgl0rlEE/s1600/vibo_02.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhPf_duawF3w6_tEqhCcWVHbJsqOzeL7IqaF1aeZyQbYX2iIcGJLYLNVmy_8bIFTWYcL73VSnofvqaIuaHEltVSBE4NMug4-rpEK3gXxiGmg3GL_suPsg2LZIFUGPnh7wtQrLjNgl0rlEE/s1600/vibo_02.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
輸入手機號碼：&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhr9t4Ez-dwwJzEWEbmhxzslXkMQJAVEgNHtzLnCmOUE2eG0XoqBqRNKamxlHt1OnvO-tpLzjlfRM1rlRgUrfHLzIpVdjKogB0QfVsNL1qEVMViH-xwaZ8rnCkW8WOu2Gy7mMq7-yyB6Go/s1600/vibo_04.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhr9t4Ez-dwwJzEWEbmhxzslXkMQJAVEgNHtzLnCmOUE2eG0XoqBqRNKamxlHt1OnvO-tpLzjlfRM1rlRgUrfHLzIpVdjKogB0QfVsNL1qEVMViH-xwaZ8rnCkW8WOu2Gy7mMq7-yyB6Go/s1600/vibo_04.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
「已將密碼以簡訊方式傳至您的手機」&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiw0rdm78Qpi9h4cOLU9eiWs77SxC3nlXDZoT53BSa5qjWXenKB9CmoKkJL-ut-xrLQM6NlKovSM1pNsOmxRrzNVkCcboUMhHagrdYD60uHTu9XhcS7GyJrZRAGvXAbx3GnbnDYYCd4x2M/s1600/vibo_05.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiw0rdm78Qpi9h4cOLU9eiWs77SxC3nlXDZoT53BSa5qjWXenKB9CmoKkJL-ut-xrLQM6NlKovSM1pNsOmxRrzNVkCcboUMhHagrdYD60uHTu9XhcS7GyJrZRAGvXAbx3GnbnDYYCd4x2M/s1600/vibo_05.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
就這樣？&lt;br /&gt;
讓我們來看看手機...&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgfCzGF-37zuv3XYg0LMkYV2qYEmIAf77jkLdD-0dsYvdhelcOTDqex47zEwvXEcATdDUBqp4iwQuIKqnRIzHbL8lX7DieRaCq93x_Dc5jU5ikDrR-lQEe9n3MASQguKHhJJqllxuvcI24/s1600/vibo_06.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;640&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgfCzGF-37zuv3XYg0LMkYV2qYEmIAf77jkLdD-0dsYvdhelcOTDqex47zEwvXEcATdDUBqp4iwQuIKqnRIzHbL8lX7DieRaCq93x_Dc5jU5ikDrR-lQEe9n3MASQguKHhJJqllxuvcI24/s640/vibo_06.png&quot; width=&quot;360&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
這樣真的好嗎？&lt;br /&gt;
有興趣的使用者可以一起驗證一下。&lt;br /&gt;
&lt;br /&gt;
密碼還是得要不能還原才安全啊...&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;「威寶電信」密碼沒加密！&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;
&lt;br /&gt;
日期：2013-10-03&lt;br /&gt;
名稱：威寶電信&lt;br /&gt;
網址：&lt;a href=&quot;http://www.vibo.com.tw/&quot;&gt;http://www.vibo.com.tw/&lt;/a&gt;&lt;br /&gt;
結果：密碼沒加密
&lt;br /&gt;
&lt;br /&gt;
感謝 Anonymous 的投稿！&lt;br /&gt;
&lt;br /&gt;</content><link rel='replies' type='application/atom+xml' href='http://plainpass.com/feeds/3085104136273060706/comments/default' title='張貼留言'/><link rel='replies' type='text/html' href='http://plainpass.com/2013/10/vibo-stores-passwords-in-plaintext.html#comment-form' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/3085104136273060706'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/3085104136273060706'/><link rel='alternate' type='text/html' href='http://plainpass.com/2013/10/vibo-stores-passwords-in-plaintext.html' title='「威寶電信」密碼沒加密！'/><author><name>Allen Own</name><uri>http://www.blogger.com/profile/07432128723498860159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgOTtJR54trZACfSZ1S-GfX8dHsYH3aLjRW6yUlr-mhSJ5cHFa2f0iPvaOYEB_AGShQpwl0tFbllzbdVooCPAh2wXx0OaEUOP6mdEB5n-yOUmnDwJC4LQ2gHlp7I4Z4Lk/s220/A2.png'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiVl6_5y3296TfRs-6V0hv_eo9BjT2_ZzZ8ajmkfOztVz6T2R6CFFtKWTEBZxJtrZ8qwTSuQ0CADepmhyfXpggqJJM7H8Q3Q_08mUTPg69TVXk34C_glqmhQiEb21KFVY2wM4CCEkWLaOM/s72-c/vibo_01.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4521309719030850665.post-4504736445030152933</id><published>2013-10-15T23:17:00.001+08:00</published><updated>2013-10-15T23:28:52.322+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="PlainPass"/><category scheme="http://www.blogger.com/atom/ns#" term="Shopping"/><category scheme="http://www.blogger.com/atom/ns#" term="Taiwan"/><category scheme="http://www.blogger.com/atom/ns#" term="Ticket"/><category scheme="http://www.blogger.com/atom/ns#" term="Travel"/><title type='text'>「ezfly 易飛網」密碼沒加密！</title><content type='html'>「&lt;a href=&quot;http://www.ezfly.com/&quot; target=&quot;_blank&quot;&gt;ezfly 易飛網&lt;/a&gt;」是個知名旅遊售票網站，國內外旅行想要訂票到這邊就對了。&lt;br /&gt;
&lt;br /&gt;
但是這麼一個老字號的旅遊網站，資訊安全到底做得怎樣呢？&lt;br /&gt;
全站都可以走 HTTPS 沒錯，但只有部分的元件有 HTTPS，這中間也隱含了一些隱憂。&lt;br /&gt;
&lt;br /&gt;
至於其他部分的安全做得好嗎？&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgfi3NfU54_Uz9HCPOeWMDQxsCR8jSzA47njNlZeA3lDKq1xX0YeJvQvhQmTmmXziN43Iq1_2nsS9rs6jIlVVOf8JsrmC_FSDqHZ0c2bfa5xGYNJvcM5VOIvtuRREJKVnoxkDCE8gMivoo/s1600/ezfly01.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;466&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgfi3NfU54_Uz9HCPOeWMDQxsCR8jSzA47njNlZeA3lDKq1xX0YeJvQvhQmTmmXziN43Iq1_2nsS9rs6jIlVVOf8JsrmC_FSDqHZ0c2bfa5xGYNJvcM5VOIvtuRREJKVnoxkDCE8gMivoo/s640/ezfly01.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
最近朋友轉了一封信給我，內容是這樣的。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgWeGKM-imGIiOoROJsI-LvHMMkJRdp28ut_Rvsx5DkmorLRUnsNlRyq2XATljav6pAPrECiLjjTP1M905GWDlLnZ3gQM3jPWKpKvDKQmhL2VAF6RfpOxG_9RgKHgXsWRpFPpWGERJrKOc/s1600/ezfly11.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;346&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgWeGKM-imGIiOoROJsI-LvHMMkJRdp28ut_Rvsx5DkmorLRUnsNlRyq2XATljav6pAPrECiLjjTP1M905GWDlLnZ3gQM3jPWKpKvDKQmhL2VAF6RfpOxG_9RgKHgXsWRpFPpWGERJrKOc/s640/ezfly11.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
全站更換密碼？這個聽起來不是很單純。不過我們還是重頭來看一下該站密碼有沒有加密吧！&lt;br /&gt;
&lt;br /&gt;
先來註冊一下...&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEijSYzSskAfMdSn1D0DbZzLL_igLwRrzjvSwYXfIQgnaYk-DRkrhwjQwRb_1LjUjtsCLgpeRBEYWRI0ZHTC4IzcN6Qox-jaF5QN4CNSGLjOA-Uf7ffXgZhdDN2JnoIhc5Pgt8UUCJxBbEY/s1600/ezfly02.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;466&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEijSYzSskAfMdSn1D0DbZzLL_igLwRrzjvSwYXfIQgnaYk-DRkrhwjQwRb_1LjUjtsCLgpeRBEYWRI0ZHTC4IzcN6Qox-jaF5QN4CNSGLjOA-Uf7ffXgZhdDN2JnoIhc5Pgt8UUCJxBbEY/s640/ezfly02.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
值得一提的是，該站有特別針對個資法來做處理，提醒你們我要用你們的個資喔！&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiZaCC4fMkgf_vFhGCvrpaLIkPuTm6OwmNJg5AIYx5hVKoYGTSTL41eHOIhZi_JI9HgMPWol___-22gmBfBWl96JEYU9k5RELKRNMECf0lHgaBJTRcObtg9a61AMH8RVlpkCGmODY-bj-U/s1600/ezfly03.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;232&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiZaCC4fMkgf_vFhGCvrpaLIkPuTm6OwmNJg5AIYx5hVKoYGTSTL41eHOIhZi_JI9HgMPWol___-22gmBfBWl96JEYU9k5RELKRNMECf0lHgaBJTRcObtg9a61AMH8RVlpkCGmODY-bj-U/s640/ezfly03.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
加入成功！&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjxR6_zKmMlDB-oKVWDc1HBQRXkumQ5uyr1vAGzc6qyHcTo6HVm1-sxPskM0xqaZnobzsqOqVEA6cpzPtzL0G0PU3KcBe6w1ZM4wKj-5ATCDj5DdH_M2RSzP5HqPnO_C5dI3yD7p4wWpwk/s1600/ezfly04.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;466&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjxR6_zKmMlDB-oKVWDc1HBQRXkumQ5uyr1vAGzc6qyHcTo6HVm1-sxPskM0xqaZnobzsqOqVEA6cpzPtzL0G0PU3KcBe6w1ZM4wKj-5ATCDj5DdH_M2RSzP5HqPnO_C5dI3yD7p4wWpwk/s640/ezfly04.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
收到信了，雖然是把密碼寄給我們了，但是也不能排除他是先寄出再加密存進資料庫的。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg48hrixNd5wOB3nCL7BBEAhe4Z8e4i_M3CBExcgLnGB6ZPqqygLKY-klE9DMSfYNXL2wIAXKu20gETjjMBDSb_C5DmpFrEsoCpF0E02mEGwgHkQS8eod8sKPRlHi3eZnrCkcWHo-C6gRI/s1600/ezfly05.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;640&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg48hrixNd5wOB3nCL7BBEAhe4Z8e4i_M3CBExcgLnGB6ZPqqygLKY-klE9DMSfYNXL2wIAXKu20gETjjMBDSb_C5DmpFrEsoCpF0E02mEGwgHkQS8eod8sKPRlHi3eZnrCkcWHo-C6gRI/s640/ezfly05.png&quot; width=&quot;602&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
沒問題，沒加密先生。讓我們來忘記密碼吧。&lt;br /&gt;
輸入帳號以及生日（都是不難取得的資訊）...&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjw-Ty_99tsKfj8LiDMSBE-t9RlizR1zGfHwzamcMFtQw63-mad4HoEjUTzLS-r4TthY7LbLMNL_A_Xj6944ApDaF0mDfrGWutrhNJzUHuOpWHpLj_Te-uSb25YwJrAzvYQ3-xva7zfjvM/s1600/ezfly06.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;466&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjw-Ty_99tsKfj8LiDMSBE-t9RlizR1zGfHwzamcMFtQw63-mad4HoEjUTzLS-r4TthY7LbLMNL_A_Xj6944ApDaF0mDfrGWutrhNJzUHuOpWHpLj_Te-uSb25YwJrAzvYQ3-xva7zfjvM/s640/ezfly06.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
給了密碼的提示，我們點選「請E-Mail密碼給我」。從選項中彷彿已經知道答案...&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiyXtIwLAStLIk-QqA11tzt52OvBseeSQjylFg-2yCAi3CyLmLElbKYZauU_05suu7ONKl_s5YAjVGPksvbYhWW-Gr3XuBsrnDwfqC-qdhqBXSHvRoF5tCz5GhZ329FOPstLr9j0IP4RZY/s1600/ezfly07.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;466&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiyXtIwLAStLIk-QqA11tzt52OvBseeSQjylFg-2yCAi3CyLmLElbKYZauU_05suu7ONKl_s5YAjVGPksvbYhWW-Gr3XuBsrnDwfqC-qdhqBXSHvRoF5tCz5GhZ329FOPstLr9j0IP4RZY/s640/ezfly07.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
密碼已經寄出！&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhmLWX4wUrmnIllAoEYQtjsRFzEcZFgdrMhBh6pvajssYn1iyVKVzB4u8Lb8v_9NyfHwXiB-3VyfYXc0Av0ZaDtQ6cUMiKaFueH7cxTUUgpiGQHJMlLLB9FZ3qbaS1vmx7ZHovZSTku3nE/s1600/ezfly08.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;466&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhmLWX4wUrmnIllAoEYQtjsRFzEcZFgdrMhBh6pvajssYn1iyVKVzB4u8Lb8v_9NyfHwXiB-3VyfYXc0Av0ZaDtQ6cUMiKaFueH7cxTUUgpiGQHJMlLLB9FZ3qbaS1vmx7ZHovZSTku3nE/s640/ezfly08.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;
收到密碼啦！正是我們所設定的「plainpass123」。&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiPdQipNY4w1oEBSqcLRai2zzq3HkCD1v45QXlsnkur4mtyKE3wVyrwl4yU1TMCx5_d8haifBhjroIeJcNc0ud1syxVJ68rtTZMmFRwIg20X9VqiipSTiaz805EOnazxF4U4zDtH-oYKxU/s1600/ezfly12.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;450&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiPdQipNY4w1oEBSqcLRai2zzq3HkCD1v45QXlsnkur4mtyKE3wVyrwl4yU1TMCx5_d8haifBhjroIeJcNc0ud1syxVJ68rtTZMmFRwIg20X9VqiipSTiaz805EOnazxF4U4zDtH-oYKxU/s640/ezfly12.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;
在測試的過程中發現一個小插曲。&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;
因為想要修改個人資料，所以登入帳號密碼修改。&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;
但是怎樣都無法登入，密碼也確定沒錯。&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;
心中漸漸開始懷疑一件事情，點開開發者工具一看...&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjNnNJsYM6Yiw5XdwRRsBbqYVXPqdCryW556XwBAeKxYfgjLHqblCNuhoqr81j2Ai5hqBGXahAujGn6em2qauxtAlUaaSdIdM8x2NS2SPuHpsm0SwOWkjz-qfwaMAVyROZBW9rP74shzHM/s1600/ezfly10.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot; target=&quot;_blank&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;466&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjNnNJsYM6Yiw5XdwRRsBbqYVXPqdCryW556XwBAeKxYfgjLHqblCNuhoqr81j2Ai5hqBGXahAujGn6em2qauxtAlUaaSdIdM8x2NS2SPuHpsm0SwOWkjz-qfwaMAVyROZBW9rP74shzHM/s640/ezfly10.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;blockquote class=&quot;tr_bq&quot;&gt;
&amp;lt;input type=&quot;password&quot; name=&quot;mbrPwd&quot; size=&quot;10&quot; maxlength=&quot;8&quot;&amp;gt;&amp;nbsp;&lt;/blockquote&gt;
該站的密碼建議是，&lt;span style=&quot;color: red;&quot;&gt;密碼請超過 8 個字&lt;/span&gt;。沒錯，8 個字的密碼真的已經太不安全了。該網站也提倡說密碼要長些。但是在修改個人資料的密碼欄位竟然最多只能輸入 8 個字...&lt;br /&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
這應該是因為舊系統原本的密碼長度上限是 8 個字吧？&lt;/div&gt;
&lt;div&gt;
記得改一下系統啊！沒人反應嗎？&lt;br /&gt;
&lt;br /&gt;
測試完畢囉！希望大家的網站安全能夠更上一步。&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;「ezfly 易飛網」密碼沒加密！&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
日期：2013-10-14&lt;br /&gt;
名稱：ezfly 易飛網&lt;br /&gt;
網址：&lt;a href=&quot;http://www.ezfly.com/&quot;&gt;http://www.ezfly.com/&lt;/a&gt;&lt;br /&gt;
結果：密碼沒加密
&lt;br /&gt;
&lt;br /&gt;
感謝 Yuan-Chung Hsiao、Ching Chung Chen、Yu-Jie Shiao、Ant 的爆料！&lt;br /&gt;
&lt;br /&gt;&lt;/div&gt;
</content><link rel='replies' type='application/atom+xml' href='http://plainpass.com/feeds/4504736445030152933/comments/default' title='張貼留言'/><link rel='replies' type='text/html' href='http://plainpass.com/2013/10/ezfly-stores-passwords-in-plaintext.html#comment-form' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/4504736445030152933'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/4504736445030152933'/><link rel='alternate' type='text/html' href='http://plainpass.com/2013/10/ezfly-stores-passwords-in-plaintext.html' title='「ezfly 易飛網」密碼沒加密！'/><author><name>Allen Own</name><uri>http://www.blogger.com/profile/07432128723498860159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgOTtJR54trZACfSZ1S-GfX8dHsYH3aLjRW6yUlr-mhSJ5cHFa2f0iPvaOYEB_AGShQpwl0tFbllzbdVooCPAh2wXx0OaEUOP6mdEB5n-yOUmnDwJC4LQ2gHlp7I4Z4Lk/s220/A2.png'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgfi3NfU54_Uz9HCPOeWMDQxsCR8jSzA47njNlZeA3lDKq1xX0YeJvQvhQmTmmXziN43Iq1_2nsS9rs6jIlVVOf8JsrmC_FSDqHZ0c2bfa5xGYNJvcM5VOIvtuRREJKVnoxkDCE8gMivoo/s72-c/ezfly01.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4521309719030850665.post-9200656870421588156</id><published>2013-10-06T20:49:00.002+08:00</published><updated>2013-10-09T04:51:30.089+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Article"/><category scheme="http://www.blogger.com/atom/ns#" term="PlainPass"/><title type='text'>什麼是「加密」？什麼是「沒加密」？</title><content type='html'>什麼是「加密」？什麼是「沒加密」？&lt;br /&gt;
&lt;br /&gt;
開站以來，一直不斷有人來詢問這個問題。正好今天有一則新聞分享給各位。&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://dazzlepod.com/ahashare/&quot;&gt;http://dazzlepod.com/ahashare/&lt;/a&gt;&lt;br /&gt;
&lt;blockquote class=&quot;tr_bq&quot;&gt;
AhaShare&lt;br /&gt;
cleartext passwords&lt;br /&gt;
&lt;br /&gt;
On October 4, 2013, @SQLiNairb released the entire MySQL database dump (2.7GB) from a torrent site, ahashare.com. The dump includes approximately 170,000 unique emails and passwords hashed with unsalted MD5. SQLiNairb announced the release in a Twitter post at &lt;a href=&quot;https://twitter.com/SQLiNairb/status/385944009945784320&quot;&gt;https://twitter.com/SQLiNairb/status/385944009945784320&lt;/a&gt;. There appear to be no public announcement on the leak from ahashare.com at the time of this publication.&lt;/blockquote&gt;
AhaShare 是一個 torrent 網站，一如駭客常見的手法，網站遭到入侵之後，發現使用的權限是 root，於是把整個網站資料庫 dump 出來，放置到網路上給大家下載。裡面包含了使用者了帳號（E-mail）密碼 hash （unsalted）。&lt;br /&gt;
&lt;br /&gt;
注意到了嗎？網站上把這種也標了「cleartext password」也就是「明文密碼」的意思。明文密碼的問題就是本站一直以來提倡大眾注意的問題。這類型的密碼可以簡單的提供給駭客利用，不管是破解其他人的密碼或者是盜用你的帳號。&lt;br /&gt;
&lt;br /&gt;
回到主題，那什麼是「加密」？什麼是「沒加密」？&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;span style=&quot;color: red; font-size: large;&quot;&gt;只要是駭客可以輕易取得、還原的密碼，都視同沒有加密。&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
為什麼？今天駭客如果已經入侵你的伺服器，若你的密碼沒加密，當然駭客可以直接取走。若你的密碼使用「可解密」的加密，駭客依舊可以取得解密的方法進行解密，取得原本密碼。我們直接列出以下情境給各位參考...&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;1. 密碼沒加密&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
駭客直接拿走密碼，順便謝謝你的大恩，把密碼張貼到網路上替你增加曝光度。&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;2. 密碼使用可解密（可逆）演算法加密&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
駭客取走加密字串。因為伺服器中一定含有解密方式，直接取用解密方法把密碼解密，取得密碼。&lt;br /&gt;
&lt;span style=&quot;font-size: x-small;&quot;&gt;（若是金融等級的安全，使用硬體解密金鑰等另當別論，這對駭客來說難度偏高，應會使用其他方式入侵。）&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;3. 密碼使用不可逆演算法加密&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
駭客取走加密字串。但因不可逆的演算法使用了常用、含有漏洞的演算法（MD5），直接使用破解程式（CPU、分散式處理、GPU、RainbowTable、線上服務）進行破解，取得密碼。&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;4. 密碼加鹽（salt）後使用可靠不可逆演算法加密&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
駭客取走加密字串。但因密碼有 salt，因此無法使用現成 RainbowTable 或線上服務進行解密。只能自己撰寫程式破解，增加駭客時間成本。&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
還是不懂嗎？我們舉例來說。&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhGfeQwpd28ujazw5Ar3yu1TeC8T8fFXFSOmOXpEYlTjnNRplkprQoeBBTQIxBhE9GEpvEZCfvUsSszjmAuXm4_KMyNAs49trjHS56vB4TLLCDT0n292-N7CzUj9CFwZXT9QLblTMW6nsI/s1600/Keynote.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;420&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhGfeQwpd28ujazw5Ar3yu1TeC8T8fFXFSOmOXpEYlTjnNRplkprQoeBBTQIxBhE9GEpvEZCfvUsSszjmAuXm4_KMyNAs49trjHS56vB4TLLCDT0n292-N7CzUj9CFwZXT9QLblTMW6nsI/s640/Keynote.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
「this is a password」是 18 個字元的密碼，雖然長度很夠，但明文大家都知道不安全。「dGhpcyBpcyBhIHBhc3N3b3Jk」看起來就是個加密過的字串，很安全，對吧？&lt;br /&gt;
&lt;br /&gt;
錯！大錯特錯！可還原的密碼就像是「dGhpcyBpcyBhIHBhc3N3b3Jk」一般不安全，這個是使用 base64 加密，可以直接使用工具解密回「this is a password」。有的業者直接跟我說，他們的網站有使用 base64 「&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;加密&lt;/span&gt;&lt;/b&gt;」，當場實在是震撼久久無法回神...&lt;br /&gt;
&lt;br /&gt;
「2986b7f0cd0ba9827ace0810c8818825」使用 &lt;a href=&quot;http://en.wikipedia.org/wiki/MD5&quot; target=&quot;_blank&quot;&gt;MD5&lt;/a&gt;&amp;nbsp;運算，因為 MD5 是不可逆的 one-way hash ，確實是安全的。但是在 2004 年中國密碼學家「&lt;a href=&quot;http://zh.wikipedia.org/zh-tw/%E7%8E%8B%E5%B0%8F%E9%9B%B2&quot; target=&quot;_blank&quot;&gt;王小雲&lt;/a&gt;」找到了 MD5 演算法的弱點（2005 年找到 SHA-1 的弱點），導致 MD5 / SHA-1 的安全性遭到質疑（例如簽章）。而且，MD5 的流通性高，很多資安研究員已經針對 MD5 製作了對照表。因此大家只要上網搜尋這段 hash 應該就可以找到對應的密碼。這樣還能稱作安全嗎？你放心嗎？&lt;br /&gt;
&lt;blockquote class=&quot;tr_bq&quot;&gt;
&lt;a href=&quot;https://www.google.com.tw/search?q=2986b7f0cd0ba9827ace0810c8818825&quot;&gt;https://www.google.com.tw/search?q=2986b7f0cd0ba9827ace0810c8818825&lt;/a&gt;&lt;/blockquote&gt;
「2f0e768999c07f4666545c0b669af9ed」是加了 salt 的 MD5 運算。上網搜尋已經找不到此密碼的結果，就算使用線上密碼破解服務也暫時無法破解。因為原始密碼加上 salt 之後長度也已經夠長，hash 已經難以被破解。這就是我們一直提倡密碼要加 salt 的原因。&lt;br /&gt;
&lt;br /&gt;
InsiderPro 網站上有提供密碼加密服務，大家可以上去體會一下加密的感覺。&lt;br /&gt;
&lt;a href=&quot;http://www.insidepro.com/hashes.php&quot;&gt;http://www.insidepro.com/hashes.php&lt;/a&gt;&lt;br /&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
想要知道我們要怎麼去選用足夠安全的加密法？可以參考之前&amp;nbsp;yftzeng (Ant)&amp;nbsp;的文章「&lt;a href=&quot;http://plainpass.com/2012/06/best-practicing-for-password-protection.html&quot; target=&quot;_blank&quot;&gt;Best Practicing for Password Protection&lt;/a&gt;」。&lt;br /&gt;
&lt;br /&gt;
什麼是「加密」？什麼是「沒加密」？如果不能提供有效、可靠、不可逆的加密法，駭客依舊可以輕易的突破你的「加密」，密碼就跟沒加密一樣了。安全性跟便利性是很難兼顧的，若是為了使用者的方便而犧牲安全，那業者們就真的要思考一下哪些是比較重要的了。若你的系統固若金湯，當然你的密碼全部設成「123456」也不用去思考安全問題。但，駭客是不好惹的，不是嗎？;)&lt;br /&gt;
&lt;br /&gt;
願我們都有個安全的系統！&lt;br /&gt;
&lt;br /&gt;
Update: 感謝 Roland, Vincent 等人的指點，更新修正文章內令人誤會的部份。</content><link rel='replies' type='application/atom+xml' href='http://plainpass.com/feeds/9200656870421588156/comments/default' title='張貼留言'/><link rel='replies' type='text/html' href='http://plainpass.com/2013/10/to-encrypt-or-not-to-encrypt.html#comment-form' title='1 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/9200656870421588156'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/9200656870421588156'/><link rel='alternate' type='text/html' href='http://plainpass.com/2013/10/to-encrypt-or-not-to-encrypt.html' title='什麼是「加密」？什麼是「沒加密」？'/><author><name>Allen Own</name><uri>http://www.blogger.com/profile/07432128723498860159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgOTtJR54trZACfSZ1S-GfX8dHsYH3aLjRW6yUlr-mhSJ5cHFa2f0iPvaOYEB_AGShQpwl0tFbllzbdVooCPAh2wXx0OaEUOP6mdEB5n-yOUmnDwJC4LQ2gHlp7I4Z4Lk/s220/A2.png'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhGfeQwpd28ujazw5Ar3yu1TeC8T8fFXFSOmOXpEYlTjnNRplkprQoeBBTQIxBhE9GEpvEZCfvUsSszjmAuXm4_KMyNAs49trjHS56vB4TLLCDT0n292-N7CzUj9CFwZXT9QLblTMW6nsI/s72-c/Keynote.png" height="72" width="72"/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4521309719030850665.post-5974588185162585614</id><published>2013-10-05T15:40:00.000+08:00</published><updated>2013-10-05T16:20:13.146+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Shopping"/><category scheme="http://www.blogger.com/atom/ns#" term="Taiwan"/><title type='text'>「PChome線上購物 - 24h購物」密碼沒加密！</title><content type='html'>&lt;div&gt;
&lt;div&gt;
「&lt;a href=&quot;http://24h.pchome.com.tw/&quot; target=&quot;_blank&quot;&gt;PChome 線上購物&lt;/a&gt;」已經是現代人購物的最愛，便宜、24hr到貨、可七天退貨，都讓人非常滿意。&lt;/div&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
還記得本站以前的文章嗎？&lt;a href=&quot;http://plainpass.com/2011/11/pchome-online-store-your-password-in.html&quot; target=&quot;_blank&quot;&gt;「PChome Online 網路家庭」會員密碼沒加密&amp;nbsp;&lt;/a&gt;。那線上購物呢？讓我們來看看網友 Ding 的爆料。&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
因為網站的找回密碼要用手機簡訊，因此我們直接把自已的帳號修改密碼，本例改為「plaintext」。&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhjHS3tia5uZHjs89jTf2rjkatn2fxwbt2cLnC_vFHhHvxcBd_C-BLQ3gKAxQ5iBwJAE1agleX09TS-vHkEtIIEmeNvqxHbtNkuPR8f-X0-l2JxTDg-VP7IOp5jfzKmmYnOnA4qlNCYT9I/s1600/pchome24_1.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;460&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhjHS3tia5uZHjs89jTf2rjkatn2fxwbt2cLnC_vFHhHvxcBd_C-BLQ3gKAxQ5iBwJAE1agleX09TS-vHkEtIIEmeNvqxHbtNkuPR8f-X0-l2JxTDg-VP7IOp5jfzKmmYnOnA4qlNCYT9I/s640/pchome24_1.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
密碼變更完成！&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhtwrNauJBCp5YD0uC5eoHN2T8ldYFwaroLXebAHcQ4fd7Uz8pCLcsxkK9LY-zLBUqyrVj-tYnEmQi_kpMsLK1sc6jn12_IbRxRhzRetP5pRUCQ6suoobMjjdykha6nzA6GcfVrIvVMD3o/s1600/pchome24_2.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;460&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhtwrNauJBCp5YD0uC5eoHN2T8ldYFwaroLXebAHcQ4fd7Uz8pCLcsxkK9LY-zLBUqyrVj-tYnEmQi_kpMsLK1sc6jn12_IbRxRhzRetP5pRUCQ6suoobMjjdykha6nzA6GcfVrIvVMD3o/s640/pchome24_2.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
下一步我想大家都很清楚，讓我們馬上使用「忘記密碼」功能來找回密碼。「PChome線上購物」需要使用手機來找回密碼，因此我們也需要輸入手機號碼。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiz4NZMtsFO7N_C9UUwoXgmIww_nDfyHrWg0aZmUapeGIYwuKnYI9AtcMAe7zBKCpJkSevshKHMIrJoqOEJUhWXsKJVKLiCpkuP2z0AfZWiASqtzuPyqFLAk3qy6nD9NdsUL2crz4wEqbc/s1600/pchome24_3.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;460&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiz4NZMtsFO7N_C9UUwoXgmIww_nDfyHrWg0aZmUapeGIYwuKnYI9AtcMAe7zBKCpJkSevshKHMIrJoqOEJUhWXsKJVKLiCpkuP2z0AfZWiASqtzuPyqFLAk3qy6nD9NdsUL2crz4wEqbc/s640/pchome24_3.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;blockquote class=&quot;tr_bq&quot;&gt;
「密碼已經利用簡訊發送到手機內。」&lt;/blockquote&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjxRZjZ8JQ4n_e-IXYWCbfrzeOfsQhQsco11VtfDxtxMbZuYSS38UZPQ6hflD6GQekSlTI5Dz7y-CzB9ZTqQjsasVBIY9HUilpPHPvphF2Btwcdui41OHQLNcaw-JxT8N2f69cNCuKQAY4/s1600/pchome24_4.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;460&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjxRZjZ8JQ4n_e-IXYWCbfrzeOfsQhQsco11VtfDxtxMbZuYSS38UZPQ6hflD6GQekSlTI5Dz7y-CzB9ZTqQjsasVBIY9HUilpPHPvphF2Btwcdui41OHQLNcaw-JxT8N2f69cNCuKQAY4/s640/pchome24_4.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
讓我們打開手機來看看簡訊...&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj1k3_T2s9F6FQC0SmtHKnn4Q_iROS-1x7mwjELFAC1jtJiitoiwvAB9joGvKz222mQIm63ufHqayHChEDipelxLtsbQBD26ThSo0rEgMQHGh0nsCjHBm6bYhukQeOcmSE1Tgn5dVNPZds/s1600/pchome24_5.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;640&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj1k3_T2s9F6FQC0SmtHKnn4Q_iROS-1x7mwjELFAC1jtJiitoiwvAB9joGvKz222mQIm63ufHqayHChEDipelxLtsbQBD26ThSo0rEgMQHGh0nsCjHBm6bYhukQeOcmSE1Tgn5dVNPZds/s640/pchome24_5.png&quot; width=&quot;360&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div&gt;
確實為我們所設定的密碼！&lt;/div&gt;
&lt;div&gt;
PChome 在這一塊真的要多小心了...&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;「PChome線上購物 - 24h購物」密碼沒加密！&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
日期：2012-05-30&lt;br /&gt;
&lt;div&gt;
名稱：PChome線上購物 - 24h購物&lt;/div&gt;
&lt;div&gt;
網址：&lt;a href=&quot;http://24h.pchome.com.tw/&quot;&gt;http://24h.pchome.com.tw&lt;/a&gt;&lt;/div&gt;
&lt;div&gt;
結果：密碼沒加密&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
感謝 Ding 的爆料！&lt;/div&gt;
</content><link rel='replies' type='application/atom+xml' href='http://plainpass.com/feeds/5974588185162585614/comments/default' title='張貼留言'/><link rel='replies' type='text/html' href='http://plainpass.com/2013/10/pchome-24hr-stores-passwords-in-plaintext.html#comment-form' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/5974588185162585614'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/5974588185162585614'/><link rel='alternate' type='text/html' href='http://plainpass.com/2013/10/pchome-24hr-stores-passwords-in-plaintext.html' title='「PChome線上購物 - 24h購物」密碼沒加密！'/><author><name>Allen Own</name><uri>http://www.blogger.com/profile/07432128723498860159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgOTtJR54trZACfSZ1S-GfX8dHsYH3aLjRW6yUlr-mhSJ5cHFa2f0iPvaOYEB_AGShQpwl0tFbllzbdVooCPAh2wXx0OaEUOP6mdEB5n-yOUmnDwJC4LQ2gHlp7I4Z4Lk/s220/A2.png'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhjHS3tia5uZHjs89jTf2rjkatn2fxwbt2cLnC_vFHhHvxcBd_C-BLQ3gKAxQ5iBwJAE1agleX09TS-vHkEtIIEmeNvqxHbtNkuPR8f-X0-l2JxTDg-VP7IOp5jfzKmmYnOnA4qlNCYT9I/s72-c/pchome24_1.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4521309719030850665.post-8575987456897724514</id><published>2013-10-01T21:34:00.000+08:00</published><updated>2013-10-01T21:34:12.604+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="PlainPass"/><category scheme="http://www.blogger.com/atom/ns#" term="Shopping"/><category scheme="http://www.blogger.com/atom/ns#" term="Taiwan"/><category scheme="http://www.blogger.com/atom/ns#" term="Ticket"/><title type='text'>「華娛售票」密碼沒加密！</title><content type='html'>「&lt;a href=&quot;http://www.walkieticket.com/&quot; target=&quot;_blank&quot;&gt;華娛售票&lt;/a&gt;」經常販售文藝活動門票，也包括很多歌手的演唱會。熱門歌手的搶票戰爭是非常刺激的！但是通常久久買一次票，總是會忘記密碼。在點了「忘記密碼」之後，往往會讓人無言...&lt;br /&gt;
&lt;br /&gt;
讓我們來跟著走一次流程吧！&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgm-4jg4SbiPBjFw9Imm1Vk1zEhhYd61XqMXduQEM9ncfuvFxS90kYTHmrmouswTTuLMmWOfEmQp8Ew7c_hMlTusfLoMuVUbBdIFUYxH9HURgHgOrQQG5hbj3nB91o26Ml40clqvjop8iU/s1600/walkieticket_01.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;482&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgm-4jg4SbiPBjFw9Imm1Vk1zEhhYd61XqMXduQEM9ncfuvFxS90kYTHmrmouswTTuLMmWOfEmQp8Ew7c_hMlTusfLoMuVUbBdIFUYxH9HURgHgOrQQG5hbj3nB91o26Ml40clqvjop8iU/s640/walkieticket_01.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
首先讓我們註冊一個新帳號，沒加密先生。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjKmV-cvUcSUX7kvbkUT7N2MNGfgne-S9g3nZlkzS4nWVrqbQ21RxP95eJl0ZsAp308KEEI7U3dr7xRuQUEtcH857ZSOuOjwwoMLmZG0OyCwbSVzoI8y1BaODFTQVBBrdnYh79C0ASSeUo/s1600/walkieticket_02.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;482&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjKmV-cvUcSUX7kvbkUT7N2MNGfgne-S9g3nZlkzS4nWVrqbQ21RxP95eJl0ZsAp308KEEI7U3dr7xRuQUEtcH857ZSOuOjwwoMLmZG0OyCwbSVzoI8y1BaODFTQVBBrdnYh79C0ASSeUo/s640/walkieticket_02.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&amp;nbsp;填寫完畢完整的個人資料之後，註冊成功了！&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiiDKmJyTJIuTHFVStcZ2VJfVVHbiuIxKefKdIqz_vWO4PWagEPxRe0RtcFeVJ-AK1_2XlyqyrklRQm6jl2ETYvNNm3O2Dxz07M8WfGPb9Xq3rn2Bz-XrLxsD00BTrHeoPBlIbiBWIjFvE/s1600/walkieticket_03.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;482&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiiDKmJyTJIuTHFVStcZ2VJfVVHbiuIxKefKdIqz_vWO4PWagEPxRe0RtcFeVJ-AK1_2XlyqyrklRQm6jl2ETYvNNm3O2Dxz07M8WfGPb9Xq3rn2Bz-XrLxsD00BTrHeoPBlIbiBWIjFvE/s640/walkieticket_03.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
當然馬上讓我們忘記密碼一下。&lt;br /&gt;
畫面上寫著驚悚的字串...&lt;br /&gt;
&lt;blockquote class=&quot;tr_bq&quot;&gt;
&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;您的密碼將會寄到您加入會員時所填寫的主要電子信箱&lt;/span&gt;&lt;/b&gt;&lt;/blockquote&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEifmBmpGs5DhFc9KxF7D5t8iXL_eANPRzbxot4OzgpuSYapRpluO56kGHyHpKbtgNIf9rGo1NZMRj1Mm5-0NpE_pGS7EGKkoXOvtB4wZey9IiPuvoELy70kE6YTUAlmR5Aw2Kl9tMQOtmQ/s1600/walkieticket_04.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;482&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEifmBmpGs5DhFc9KxF7D5t8iXL_eANPRzbxot4OzgpuSYapRpluO56kGHyHpKbtgNIf9rGo1NZMRj1Mm5-0NpE_pGS7EGKkoXOvtB4wZey9IiPuvoELy70kE6YTUAlmR5Aw2Kl9tMQOtmQ/s640/walkieticket_04.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
填好了，他也說請我們去收信拿密碼。&lt;br /&gt;
看來答案非常明顯了。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjF5lVxEAP2Cp_8Pb2B8ya2TgxtcjSporGD8DJ8e_Dh6RmOSwhVLICQpNrDZXuMXI2lbqm7qkJkHqpRrpSb0-ttimFIYuFOG7_B0YzlSyvYZr3Ez19FVoafGtI99LQ17M3ZSHuRPhPgtsE/s1600/walkieticket_05.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;482&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjF5lVxEAP2Cp_8Pb2B8ya2TgxtcjSporGD8DJ8e_Dh6RmOSwhVLICQpNrDZXuMXI2lbqm7qkJkHqpRrpSb0-ttimFIYuFOG7_B0YzlSyvYZr3Ez19FVoafGtI99LQ17M3ZSHuRPhPgtsE/s640/walkieticket_05.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
讓我們看看信箱：「您的密碼是：plainpass」&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi8UZhElpETKWA4QPE072z-i6txwzx_1Vls1BOBeperHrrGyutSy5QLjFUqOOx-2101pH7xqtME5qkfazSpSTho1XtOMUYn4tGQ_THKmwNMAkEhq5W6JsHY39RXQeuunwAWumFONyRtT8Y/s1600/walkieticket_06.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;486&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi8UZhElpETKWA4QPE072z-i6txwzx_1Vls1BOBeperHrrGyutSy5QLjFUqOOx-2101pH7xqtME5qkfazSpSTho1XtOMUYn4tGQ_THKmwNMAkEhq5W6JsHY39RXQeuunwAWumFONyRtT8Y/s640/walkieticket_06.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
每次買票都要經歷一次這樣的歷程，看著自己的密碼每次都被秀出來心中實在是百感交集。&lt;br /&gt;
&lt;div&gt;
希望各大售票網站都能好好改進一下啊！&lt;br /&gt;
&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;
&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;「華娛售票」密碼沒加密！&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
日期：2013-09-26&lt;br /&gt;
名稱：華娛售票&lt;br /&gt;
網址：&lt;a href=&quot;http://www.walkieticket.com/&quot;&gt;http://www.walkieticket.com&lt;/a&gt;&lt;br /&gt;
結果：密碼沒加密
&lt;/div&gt;
</content><link rel='replies' type='application/atom+xml' href='http://plainpass.com/feeds/8575987456897724514/comments/default' title='張貼留言'/><link rel='replies' type='text/html' href='http://plainpass.com/2013/10/walkieticket-stores-passwords-in-plaintext.html#comment-form' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/8575987456897724514'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/8575987456897724514'/><link rel='alternate' type='text/html' href='http://plainpass.com/2013/10/walkieticket-stores-passwords-in-plaintext.html' title='「華娛售票」密碼沒加密！'/><author><name>Allen Own</name><uri>http://www.blogger.com/profile/07432128723498860159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgOTtJR54trZACfSZ1S-GfX8dHsYH3aLjRW6yUlr-mhSJ5cHFa2f0iPvaOYEB_AGShQpwl0tFbllzbdVooCPAh2wXx0OaEUOP6mdEB5n-yOUmnDwJC4LQ2gHlp7I4Z4Lk/s220/A2.png'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgm-4jg4SbiPBjFw9Imm1Vk1zEhhYd61XqMXduQEM9ncfuvFxS90kYTHmrmouswTTuLMmWOfEmQp8Ew7c_hMlTusfLoMuVUbBdIFUYxH9HURgHgOrQQG5hbj3nB91o26Ml40clqvjop8iU/s72-c/walkieticket_01.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4521309719030850665.post-1977281567785916908</id><published>2013-09-26T17:04:00.000+08:00</published><updated>2013-09-26T17:04:21.227+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="PlainPass"/><category scheme="http://www.blogger.com/atom/ns#" term="Shopping"/><category scheme="http://www.blogger.com/atom/ns#" term="Taiwan"/><category scheme="http://www.blogger.com/atom/ns#" term="Ticket"/><category scheme="http://www.blogger.com/atom/ns#" term="Travel"/><title type='text'>「中華航空公司 China Airlines」密碼沒加密！</title><content type='html'>年底是出國遊玩的好季節，網路的時代大家也多半會在線上直接購買機票。&lt;br /&gt;
有會員的地方就有密碼，有密碼的地方就有安全的疑慮。&lt;br /&gt;
&lt;br /&gt;
讓我們今天來看看「&lt;a href=&quot;http://www.china-airlines.com/&quot; target=&quot;_blank&quot;&gt;中華航空公司 China Airlines&lt;/a&gt;」的會員密碼有沒有加密。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj5hDN9yJwkIanwp0ohm05eUB4zHI7B1qiRXXRCVCRqzGpF-eJyqDSe9JXUrKULitsAZpgcBMZb_3RreW0-rgMpiOf7HAFo17sTVn7_VDVeqBypHflRdCcN8zkqjQcMP7rmh8S5OczK7uk/s1600/China+Airlines+01.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;482&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj5hDN9yJwkIanwp0ohm05eUB4zHI7B1qiRXXRCVCRqzGpF-eJyqDSe9JXUrKULitsAZpgcBMZb_3RreW0-rgMpiOf7HAFo17sTVn7_VDVeqBypHflRdCcN8zkqjQcMP7rmh8S5OczK7uk/s640/China+Airlines+01.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
先來申請入會。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhmnBIb7Irttmg5SbMlgp0seckB5Y2yyK7kCjTytITZR6MySijWUnxnZBffvQFX6UB8rJM1mDT23WHP2eaV0JLPw-UMe-0MpCtPGcoZP9PT-Y_iOF9fhokGsidFH62jV-cJ8WJb5lYAg-4/s1600/China+Airlines+02.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;482&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhmnBIb7Irttmg5SbMlgp0seckB5Y2yyK7kCjTytITZR6MySijWUnxnZBffvQFX6UB8rJM1mDT23WHP2eaV0JLPw-UMe-0MpCtPGcoZP9PT-Y_iOF9fhokGsidFH62jV-cJ8WJb5lYAg-4/s640/China+Airlines+02.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
填寫非常完整的個人資料。我們一樣請沒加密先生來幫我們檢查一下。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgPDzXcfuYLrWMECLLMv7Ou8jivjJIwn3-D-BAbcQRJXpmeoMsgBznnI0f7Akq9LKesrpHqYYUYaOKpUW4fRZ1mY3Tye9Sdv1BZXUSqnRBMXbn1Uqt5NbUgo0sUypsEyl2_7jASzLdz9Ls/s1600/China+Airlines+03.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;482&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgPDzXcfuYLrWMECLLMv7Ou8jivjJIwn3-D-BAbcQRJXpmeoMsgBznnI0f7Akq9LKesrpHqYYUYaOKpUW4fRZ1mY3Tye9Sdv1BZXUSqnRBMXbn1Uqt5NbUgo0sUypsEyl2_7jASzLdz9Ls/s640/China+Airlines+03.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
好的，住在凱達格蘭大道一號的沒加密先生，帳號申請成功。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhamSF-S95ZWT63n5-o4RG9U-gqJHf7qbMKSThGBhq2P6ZldMOzCKGNLy3N63DKoxRYx6t7rWutoqybAAnxOFq5eG6z7utHXApMqCTfqZ_a4kRp6Wbg-dJbKSMKY26pKYCGsystrd3R9c0/s1600/China+Airlines+04.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;482&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhamSF-S95ZWT63n5-o4RG9U-gqJHf7qbMKSThGBhq2P6ZldMOzCKGNLy3N63DKoxRYx6t7rWutoqybAAnxOFq5eG6z7utHXApMqCTfqZ_a4kRp6Wbg-dJbKSMKY26pKYCGsystrd3R9c0/s640/China+Airlines+04.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
登入的方式會採用「華夏會員卡號」。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgyidoZYHhAo566_Kv70-s3GWrwCEebAgyaAUyTBX2upoqgfWo5VQ21mbrEEcGXGBrBUC0OU-K5hyphenhyphenoLJIw_3isNXlw4h48_0yQk-Sb6NNRq9zZ4B2gcFU43zgi27qoNUDvrUvPB3F7nxXw/s1600/China+Airlines+05.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;482&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgyidoZYHhAo566_Kv70-s3GWrwCEebAgyaAUyTBX2upoqgfWo5VQ21mbrEEcGXGBrBUC0OU-K5hyphenhyphenoLJIw_3isNXlw4h48_0yQk-Sb6NNRq9zZ4B2gcFU43zgi27qoNUDvrUvPB3F7nxXw/s640/China+Airlines+05.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
接著我們馬上來使用「查詢密碼」功能來看看我們的密碼。&lt;br /&gt;
既然都叫做「查詢」密碼，聽起來應該是可以看到原本的密碼...&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEihTSup7XmuFin6YVSYGwRLRB3UHEzn_88T-p2DlMR7T0mRZoFWsOgp_ZAWjVY4N9_1BgZPG_UJPq4dUyw5vb6dG7iiClUocJzwLoHCJqA3_ggr2594tP7PDLomK7qZJh4RDCoUQaeLVAE/s1600/China+Airlines+06.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;482&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEihTSup7XmuFin6YVSYGwRLRB3UHEzn_88T-p2DlMR7T0mRZoFWsOgp_ZAWjVY4N9_1BgZPG_UJPq4dUyw5vb6dG7iiClUocJzwLoHCJqA3_ggr2594tP7PDLomK7qZJh4RDCoUQaeLVAE/s640/China+Airlines+06.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
輸入完畢之後，會把原本的密碼資訊寄送到註冊的信箱中。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgw5W8EU6vlyB_VJwPdJL6JZsLoA7WK4O4rlTzVgTtgiQW2DGzdLrbOePJ57f7iznldb_GLl3D0Io3asga5xc0odkJdHJ32sGjdnCVBoLos7zgVy6d7WCoHFFQ-oamHovcTcHE8BZpGqfE/s1600/China+Airlines+07.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;482&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgw5W8EU6vlyB_VJwPdJL6JZsLoA7WK4O4rlTzVgTtgiQW2DGzdLrbOePJ57f7iznldb_GLl3D0Io3asga5xc0odkJdHJ32sGjdnCVBoLos7zgVy6d7WCoHFFQ-oamHovcTcHE8BZpGqfE/s640/China+Airlines+07.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgpj_1G4M4kFKr4v9Dnc9IL4qKYOhMclYm578hOhZmjG0IOWC5uBM6iZmajMswNLxy2zVeARIjVEcl5xcRBE45dOyE00dmD-fvcft0oghWRpY_VjGQGBRUyt7b95SwsEmXO8goFGV5zBU8/s1600/China+Airlines+08.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;482&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgpj_1G4M4kFKr4v9Dnc9IL4qKYOhMclYm578hOhZmjG0IOWC5uBM6iZmajMswNLxy2zVeARIjVEcl5xcRBE45dOyE00dmD-fvcft0oghWRpY_VjGQGBRUyt7b95SwsEmXO8goFGV5zBU8/s640/China+Airlines+08.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
最後從我們的信箱中，得到我們原始的密碼「plain123」。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg65CS2Ml3nz7qluVL49kaZciw_IZoQBb7qc9dcHtJzniB8GtBO6pclu175QeZVNbPkIRqJ3JJbdBuTX0EohApCGWTPt2GsPdypRqQkrNWRMQYsTHcMWLZz2-5UfCvZj0bjuCmuBg1URec/s1600/China+Airlines+09.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;484&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg65CS2Ml3nz7qluVL49kaZciw_IZoQBb7qc9dcHtJzniB8GtBO6pclu175QeZVNbPkIRqJ3JJbdBuTX0EohApCGWTPt2GsPdypRqQkrNWRMQYsTHcMWLZz2-5UfCvZj0bjuCmuBg1URec/s640/China+Airlines+09.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
結果得知：&lt;br /&gt;
&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;「中華航空公司 China Airlines」密碼沒加密！&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
日期：2013-09-13&lt;br /&gt;
名稱：中華航空公司 China Airlines&lt;br /&gt;
網址：&lt;a href=&quot;http://www.china-airlines.com/&quot;&gt;http://www.china-airlines.com&lt;/a&gt;&lt;br /&gt;
結果：密碼沒加密&lt;br /&gt;
&lt;div&gt;
&lt;br /&gt;
感謝 Kobe Yang ＆ Kan-Ru Chen 以及許多不具名網友的爆料！&lt;/div&gt;
</content><link rel='replies' type='application/atom+xml' href='http://plainpass.com/feeds/1977281567785916908/comments/default' title='張貼留言'/><link rel='replies' type='text/html' href='http://plainpass.com/2013/09/china-airline-stores-passwords-in-plaintext.html#comment-form' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/1977281567785916908'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/1977281567785916908'/><link rel='alternate' type='text/html' href='http://plainpass.com/2013/09/china-airline-stores-passwords-in-plaintext.html' title='「中華航空公司 China Airlines」密碼沒加密！'/><author><name>Allen Own</name><uri>http://www.blogger.com/profile/07432128723498860159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgOTtJR54trZACfSZ1S-GfX8dHsYH3aLjRW6yUlr-mhSJ5cHFa2f0iPvaOYEB_AGShQpwl0tFbllzbdVooCPAh2wXx0OaEUOP6mdEB5n-yOUmnDwJC4LQ2gHlp7I4Z4Lk/s220/A2.png'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj5hDN9yJwkIanwp0ohm05eUB4zHI7B1qiRXXRCVCRqzGpF-eJyqDSe9JXUrKULitsAZpgcBMZb_3RreW0-rgMpiOf7HAFo17sTVn7_VDVeqBypHflRdCcN8zkqjQcMP7rmh8S5OczK7uk/s72-c/China+Airlines+01.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4521309719030850665.post-1567680173069588904</id><published>2013-09-21T00:10:00.000+08:00</published><updated>2013-09-21T00:10:09.512+08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="PlainPass"/><category scheme="http://www.blogger.com/atom/ns#" term="Shopping"/><category scheme="http://www.blogger.com/atom/ns#" term="Taiwan"/><category scheme="http://www.blogger.com/atom/ns#" term="Ticket"/><category scheme="http://www.blogger.com/atom/ns#" term="Travel"/><title type='text'>「EZ訂 ezDing」密碼沒加密！</title><content type='html'>「&lt;a href=&quot;http://www.ezding.com.tw/&quot; target=&quot;_blank&quot;&gt;EZ訂 ezDing&lt;/a&gt;」是「&lt;a href=&quot;http://www.fullerton.com.tw/&quot; target=&quot;_blank&quot;&gt;富爾特科技股份有限公司&lt;/a&gt;」所建置的訂購網站，包括電影、民宿等等。&lt;br /&gt;
&lt;br /&gt;
經過這麼多售票網站以來，究竟「EZ 訂」能不能夠通過 PlainPass 的檢測呢？ 讓我們來看看。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjP1u2h8L8vucy7nAhtP4GuQ30HNhEzBmFs8WtCutLP6-X-iZHy-dpUn6AN7T78HQCDPa14DzH6lEh-uqh7YITTCQf7NQKkyGEPfsFDr4ufU09bl3uHfIaZZg53Kq2XdIoCuVymEPWQf3U/s1600/ezDing_01.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;472&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjP1u2h8L8vucy7nAhtP4GuQ30HNhEzBmFs8WtCutLP6-X-iZHy-dpUn6AN7T78HQCDPa14DzH6lEh-uqh7YITTCQf7NQKkyGEPfsFDr4ufU09bl3uHfIaZZg53Kq2XdIoCuVymEPWQf3U/s640/ezDing_01.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&amp;nbsp;站內的「&lt;a href=&quot;http://www.ezding.com.tw/pages/static/member_provision.htm&quot; target=&quot;_blank&quot;&gt;會員服務條款&lt;/a&gt;」有說明了個資蒐集使用原則、安全等等。&lt;br /&gt;
&lt;blockquote class=&quot;tr_bq&quot;&gt;
一、EZ訂會員帳號即手機門號，必須詳實填寫，手機門號及密碼，不能重複登錄。除非經他人合法授權使用其個人資料以外，您如果提供任何錯誤或是不實的資料進行登錄，本網站有權暫停或是終止您的帳號，並拒絕您使用本服務。&lt;/blockquote&gt;
&lt;div&gt;
除了 SSL 之外，並沒有說對會員資料進行怎樣的防護。&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
讓我們請沒加密先生開始測試吧！&lt;/div&gt;
&lt;div&gt;
該網站使用手機號碼當做會員帳號，帳號密碼也會跟手機關連。&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiwT7evuOrAaN3sIBsptq6gCma2WUr-uORD-oG5qbLi9i3NmlH_ijujNJlHIMdGSO0R239IVvJOKUM-gYX2i47JIhLeD_hxdM0qZpss_qYu4TMfG8T0KCVmQNL2M5EgHE1KCeMdqiELnTg/s1600/ezDing_02.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;472&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiwT7evuOrAaN3sIBsptq6gCma2WUr-uORD-oG5qbLi9i3NmlH_ijujNJlHIMdGSO0R239IVvJOKUM-gYX2i47JIhLeD_hxdM0qZpss_qYu4TMfG8T0KCVmQNL2M5EgHE1KCeMdqiELnTg/s640/ezDing_02.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
簡單註冊完畢，還好不需要輸入太多個人資料。&lt;br /&gt;
馬上開始點選「忘記密碼」開始測試。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgcHXCPmWWYPcO1ugh_5t6xW9tPfj_hdvAoYdSTSkthh4qc5sjnFkxqhBoIRpEfHcJFR2cB1xMC0I0XYE_gdp3OJHzMUZMnc8ugVSVWpovU4wMX_be2oqJRZjMUyt2dWtimLJl94yxZrJ8/s1600/ezDing_03.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;472&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgcHXCPmWWYPcO1ugh_5t6xW9tPfj_hdvAoYdSTSkthh4qc5sjnFkxqhBoIRpEfHcJFR2cB1xMC0I0XYE_gdp3OJHzMUZMnc8ugVSVWpovU4wMX_be2oqJRZjMUyt2dWtimLJl94yxZrJ8/s640/ezDing_03.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
輸入手機號碼（會員帳號）以及驗證碼之後，將會寄送密碼。&lt;br /&gt;
寄送的方式很特別，除了信件之外，還會同步發送簡訊。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjMulySTRxeGnNg98URJtKBhrVYAeoxIHQanDYR9G-lyItJIwjJ4dJyBU2QpLyFiUsglyZ1NclKShSO3dF5irM7AWlxwzj1hbEnSb5HzmgY-IKvCZyck6cFCfA4rnXZhTrMTWV8MEFGb34/s1600/ezDing_04.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;472&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjMulySTRxeGnNg98URJtKBhrVYAeoxIHQanDYR9G-lyItJIwjJ4dJyBU2QpLyFiUsglyZ1NclKShSO3dF5irM7AWlxwzj1hbEnSb5HzmgY-IKvCZyck6cFCfA4rnXZhTrMTWV8MEFGb34/s640/ezDing_04.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
「您的登入密碼已經透過下列方式傳送給您」，看來答案已經出現了。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjIXBwP-X1rrqfx_gK_DhGtVAiHXkbO8TX5zd8Z9iTVIuuHsJAikbz3-eI72E9fTSq-3DrJY1LZVRSArSg9oJ3Ie_irV1-v0NWIr_lL0ApoAc5-Usd-jluPT7vt70IZlz5ZxGZ8-Vyoc3c/s1600/ezDing_05.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;472&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjIXBwP-X1rrqfx_gK_DhGtVAiHXkbO8TX5zd8Z9iTVIuuHsJAikbz3-eI72E9fTSq-3DrJY1LZVRSArSg9oJ3Ie_irV1-v0NWIr_lL0ApoAc5-Usd-jluPT7vt70IZlz5ZxGZ8-Vyoc3c/s640/ezDing_05.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
看看信箱中，確實是我們所設定的密碼。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi5Tb5ljWqlFI93N7HwEvgzBJk73nVdehwvmtYAHXS-ysecFJxPdtpFElvDPBi0KOstezlBw-9SrDyUmlZXLiKRhY8Hwy6XqFwauqEz5qZXcWmQgbZNDQtD9H0wo47xRFOmU2ZScTqno1A/s1600/ezDing_06.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi5Tb5ljWqlFI93N7HwEvgzBJk73nVdehwvmtYAHXS-ysecFJxPdtpFElvDPBi0KOstezlBw-9SrDyUmlZXLiKRhY8Hwy6XqFwauqEz5qZXcWmQgbZNDQtD9H0wo47xRFOmU2ZScTqno1A/s1600/ezDing_06.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
手機也同步收到了密碼的簡訊。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEguLg2o8434wkiggobUFkKRpurAcxolw5fus70Mn7ZpZoEKlfZ1VynZYLUZPVPM6BQM5cnpuQt0llXJHhuLqzgAsBGwaK3YJzFxfpdVuwTixzeds4aOa__hWqzr9_xy3Pz8jALwxnYHtxk/s1600/ezDing_09.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;640&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEguLg2o8434wkiggobUFkKRpurAcxolw5fus70Mn7ZpZoEKlfZ1VynZYLUZPVPM6BQM5cnpuQt0llXJHhuLqzgAsBGwaK3YJzFxfpdVuwTixzeds4aOa__hWqzr9_xy3Pz8jALwxnYHtxk/s640/ezDing_09.png&quot; width=&quot;360&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;
除此之外，如果我們點選「修改會員資料」，上面也是直接出現了我們原始的密碼。&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;
透過瀏覽器的「開發者工具」可以一目了然。&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhMBP1yp_f5PzA7RosmcHfQCLpIZGLlSGOXopN8iULxf0xUwC9SSV5vldxaXxtPt7Wwb-DqeR0j-OzrziL3yCqmfQEw6PneajZFYQK-rWW26jLHkUcp-Rlw_WxgYdQbJFDBkQuZgbbogCU/s1600/ezDing_07.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;472&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhMBP1yp_f5PzA7RosmcHfQCLpIZGLlSGOXopN8iULxf0xUwC9SSV5vldxaXxtPt7Wwb-DqeR0j-OzrziL3yCqmfQEw6PneajZFYQK-rWW26jLHkUcp-Rlw_WxgYdQbJFDBkQuZgbbogCU/s640/ezDing_07.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
同站的另一個頁面，一樣可以從個人資料中直接取得密碼。&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi2NfpFTzRiD1dn8JJYBmukY9hFmMNlyCGLm5MGNoHkMfKNJ_NEpg6vi7lJ0dJzK4MVtYenJixLuhHDgrlKK9Fr3PLA7E78yJPur7aD_Ns_xlsY_KmCWFtKdgWz5UwX7egxsk-mf7nhmkM/s1600/ezDing_08.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;472&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi2NfpFTzRiD1dn8JJYBmukY9hFmMNlyCGLm5MGNoHkMfKNJ_NEpg6vi7lJ0dJzK4MVtYenJixLuhHDgrlKK9Fr3PLA7E78yJPur7aD_Ns_xlsY_KmCWFtKdgWz5UwX7egxsk-mf7nhmkM/s640/ezDing_08.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
這樣真的好嗎？整個網站都這樣，讓消費者要如何安心的使用呢？希望你們趕快改進吧！&lt;br /&gt;
&lt;div&gt;
&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;
&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;「EZ訂 ezDing」密碼沒加密！&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
日期：2013-09-20&lt;br /&gt;
名稱：EZ訂 ezDing&lt;br /&gt;
網址：&lt;a href=&quot;http://www.ezding.com.tw/&quot;&gt;http://www.ezding.com.tw&lt;/a&gt;&lt;br /&gt;
結果：密碼沒加密
&lt;br /&gt;
&lt;br /&gt;
感謝 Tiger Huang &amp;amp; Seachaos 的爆料！&lt;/div&gt;
</content><link rel='replies' type='application/atom+xml' href='http://plainpass.com/feeds/1567680173069588904/comments/default' title='張貼留言'/><link rel='replies' type='text/html' href='http://plainpass.com/2013/09/ezding-stores-passwords-in-plaintext.html#comment-form' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/1567680173069588904'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4521309719030850665/posts/default/1567680173069588904'/><link rel='alternate' type='text/html' href='http://plainpass.com/2013/09/ezding-stores-passwords-in-plaintext.html' title='「EZ訂 ezDing」密碼沒加密！'/><author><name>Allen Own</name><uri>http://www.blogger.com/profile/07432128723498860159</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgOTtJR54trZACfSZ1S-GfX8dHsYH3aLjRW6yUlr-mhSJ5cHFa2f0iPvaOYEB_AGShQpwl0tFbllzbdVooCPAh2wXx0OaEUOP6mdEB5n-yOUmnDwJC4LQ2gHlp7I4Z4Lk/s220/A2.png'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjP1u2h8L8vucy7nAhtP4GuQ30HNhEzBmFs8WtCutLP6-X-iZHy-dpUn6AN7T78HQCDPa14DzH6lEh-uqh7YITTCQf7NQKkyGEPfsFDr4ufU09bl3uHfIaZZg53Kq2XdIoCuVymEPWQf3U/s72-c/ezDing_01.png" height="72" width="72"/><thr:total>0</thr:total></entry></feed>