F
F
Fredcapit2014-09-09 10:27:12
Yandex
Fredcapit, 2014-09-09 10:27:12

Are POST request form data encrypted when authenticating from the Yandex Home page (www.yandex.ru)?

Please tell me if the connection is encrypted when transferring form data during authentication from the main page of Yandex.
Below is a part of the POST request from the "Main" ( htttp://www.yandex.ru ) page when the "Login" button is pressed


Request URL:https://passport.yandex.ru/passport?mode=auth&...
Request Method:POST
Status Code:200 OK
Request Headers
Accept:text/html,application/xhtml+xml,application/xml;q= 0.9,image/webp,*/*;q=0.8
Accept-Encoding:gzip,deflate
Accept-Language:ru-RU,ru;q=0.8,en-US;q=0.6,en;q=0.4
Cache-Control :max-age=0
Connection:keep-alive
Content-Length:214
Content-Type:application/x-www-form-urlencoded
Cookie:fuid01=53f184ff62c3ed01.2mgeiXsSqueAq9snqLslHENPo_L87SxJqEUWzjOdBfQGgVllZgAkIzsmBQtjN1ZttlfDzFuF3TpYt2Aav6-5hyQbWbuVh9tCZGzn8dPIitneA-gO2WUlcuuQ8; L=YkokDkgBW1F5cHd6Xk8KVFwGUwdAY2gIJEA0PyV9WSkxJBs3HQchdQc3T1csBzZcB1IKVwMhLTckRhkPHRx7LA==.1410158152.11179.275070.4c45f70f9c78c626805c15da6; my=YzYBAQA=; yabs-frequency=/4/0m0100582LHle0PK/D3gmSC0QGOiwi7306c7Ppt5mm1f1qZcmSBmQ8WG40psp6YS0004EEh1mh1edn1IlSAWQPySoi72l6lp____spt5mR1gy/; yandexuid=98474201408337145; yp=1425490893.mu.1#1441344522.s5px.1#1426011658.mv.0; ys=wprid.1410246762741414-283766807225971896003588-ws22-099
Host:passport.yandex.ru
Origin:http://www.yandex.ru
Referer:http://www.yandex.ru/
User-Agent:Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/37.0.2062.103 Safari/537.36
Query String Parameters
mode:auth
retpath:https://mail.yandex.ru/? origin=log_ru_l
origin:log_ru_l
Form Dataview
login:HereMyLogin
passwd:HereMy Password
twoweeks:yes
timestamp:1410246874211

Answer the question

In order to leave comments, you need to log in

2 answer(s)
F
Fredcapit, 2014-09-09
@Fredcapit

I found the answer myself .
Thank God that everything is already provided by browsers. I just don’t know how authentication works if the user has an old browser, such as Internet Explorer 8.

V
Vlad Zhivotnev, 2014-09-10
@inkvizitor68sl

There, the action on https://passport.yandex.ru/passport?mode=auth&retpath=https%3A%2F%2Fmail.yandex.ru%2F%3Forigin%3Dlog_ru_nol&origin=log_ru_nol is explicitly registered.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question