<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Gabriel D Subba &#187; White Label Social Networks</title>
	<atom:link href="http://www.kuzzuk.net/tag/white-label-social-networks/feed" rel="self" type="application/rss+xml" />
	<link>http://www.kuzzuk.net</link>
	<description>A weblog of my personal and entrepreneurial journey</description>
	<lastBuildDate>Sat, 04 Feb 2012 23:56:02 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Security Loophole In Ning Social Networking App?</title>
		<link>http://www.kuzzuk.net/ning-social-network-security-loophole.html</link>
		<comments>http://www.kuzzuk.net/ning-social-network-security-loophole.html#comments</comments>
		<pubDate>Wed, 08 Apr 2009 12:28:29 +0000</pubDate>
		<dc:creator>Kuzzuk</dc:creator>
				<category><![CDATA[Social Media]]></category>
		<category><![CDATA[Ning]]></category>
		<category><![CDATA[White Label Social Networks]]></category>

		<guid isPermaLink="false">http://www.kuzzuk.net/?p=128</guid>
		<description><![CDATA[<p>Posted in <a href="http://www.kuzzuk.net/section/social-media" title="Social Media">Social Media</a></p>I&#8217;m not a security expert but there have been a number of cases within the social network for Darjeeling that I run (with over 1,000 members) using Ning where someone logs in as another person and wreaks havoc giving the administrators a hard time. One of our members dropped me a Facebook message informing me [...]]]></description>
			<content:encoded><![CDATA[<p>Posted in <a href="http://www.kuzzuk.net/section/social-media" title="Social Media">Social Media</a></p><p><div id="attachment_179" class="wp-caption alignleft" style="width: 410px"><img src="http://www.kuzzuk.net/wp-content/uploads/2009/04/ning-social-network-security-threat.png" alt="ning social network app security threat" title="ning social network app security threat" width="400" height="179" class="alignleft size-full wp-image-130" /><p class="wp-caption-text">Image Source: sxc.hu</p></div>I&#8217;m not a security expert but there have been a number of cases within the <a href="http://social.darjeelingews.net/">social network for Darjeeling</a> that I run (with over 1,000 members) using <a href="http://ning.com">Ning</a> where someone logs in as another person and wreaks havoc giving the administrators a hard time. </p>
<p>One of our members dropped me a Facebook message informing me of the security loophole telling me that Ning transmits email address and password in cleartext.</p>
<blockquote><p>
the site is transmitting userid and password in clear text. i know the login form with ning id is secure but there there a field named xg_token as &#8220;xg_token=&#038;emailAddress=me@gmail.com&#038;password=password&#8221; somewhere in the code that is doing this.</p></blockquote>
<p>Like I said before, I&#8217;m not an online security expert but I downloaded a sniffer from <a href="http://www.effetech.com/">Effetech</a> to test the claim using my own email address and password in Ning. I could see my password in cleartext (masked in the screenshot below). Additionally, as a logical test I tried sniffing my own Gmail username and password which was unsuccessful. In my own layman way, this probably means that the Ning password is being sent in cleartext while Gmail sends it securely.   </p>
<p><img src="http://www.kuzzuk.net/wp-content/uploads/2009/04/password-sniffer.png" alt="Password Sniffer For Ning" title="Password Sniffer For Ning" width="650" height="217" class="alignnone size-full wp-image-132" />I have informed Ning and let&#8217;s see what they have to say about it. Meanwhile, has anyone had this issue with Ning before?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.kuzzuk.net/ning-social-network-security-loophole.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

