<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Credentials are transmitted to server in plain text in Dynatrace Managed Q&amp;A</title>
    <link>https://community.dynatrace.com/t5/Dynatrace-Managed-Q-A/Credentials-are-transmitted-to-server-in-plain-text/m-p/185531#M1925</link>
    <description>&lt;P&gt;Dear Team,&lt;BR /&gt;As we have observed vulnerabilities during login, password is not encrypted after submission of dynatrace managed login page. Also attached snap as evidence for such case. Kindly check and resolve ASAP.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Observation Solution :&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;Encrypt transmission of credentials from the client to the server.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Observation Description:&lt;/STRONG&gt;&amp;nbsp;An adversary can intercept plain text credentials&amp;nbsp;using sniffer tools. Credentials&amp;nbsp;thus obtained may be used to gain unauthorized&amp;nbsp;access to the application.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards,&lt;BR /&gt;Ashutosh Kumar Singh&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 16 Jun 2023 11:04:51 GMT</pubDate>
    <dc:creator>dynatrace5</dc:creator>
    <dc:date>2023-06-16T11:04:51Z</dc:date>
    <item>
      <title>Credentials are transmitted to server in plain text</title>
      <link>https://community.dynatrace.com/t5/Dynatrace-Managed-Q-A/Credentials-are-transmitted-to-server-in-plain-text/m-p/185531#M1925</link>
      <description>&lt;P&gt;Dear Team,&lt;BR /&gt;As we have observed vulnerabilities during login, password is not encrypted after submission of dynatrace managed login page. Also attached snap as evidence for such case. Kindly check and resolve ASAP.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Observation Solution :&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;Encrypt transmission of credentials from the client to the server.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Observation Description:&lt;/STRONG&gt;&amp;nbsp;An adversary can intercept plain text credentials&amp;nbsp;using sniffer tools. Credentials&amp;nbsp;thus obtained may be used to gain unauthorized&amp;nbsp;access to the application.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards,&lt;BR /&gt;Ashutosh Kumar Singh&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2023 11:04:51 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dynatrace-Managed-Q-A/Credentials-are-transmitted-to-server-in-plain-text/m-p/185531#M1925</guid>
      <dc:creator>dynatrace5</dc:creator>
      <dc:date>2023-06-16T11:04:51Z</dc:date>
    </item>
    <item>
      <title>Re: Credentials are transmitted to server in plain text</title>
      <link>https://community.dynatrace.com/t5/Dynatrace-Managed-Q-A/Credentials-are-transmitted-to-server-in-plain-text/m-p/185533#M1926</link>
      <description>&lt;P&gt;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/7538"&gt;@dynatrace5&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;In the screenshot you provide, you can see that connection is being made in https, so the whole socket and the data transmitted in it are encrypted.&lt;/P&gt;&lt;P&gt;The fact that you are seeing the data unencrypted is because you are intercepting this with a MITM attack proxy, like BURP. For you to do it, you have had to make something special on the client side making the requests, like putting in new certificates/CAs. In a normal proxy it won't work this way.&lt;/P&gt;&lt;P&gt;If you grab the data from a packet capture, you will confirm that you cannot see it.&lt;/P&gt;&lt;P&gt;So, in summary, it is effectively encrypted, and an adversary cannot intercept such data using sniffer tools.&lt;/P&gt;&lt;P&gt;This is how https normally works. You can secure it with some additional tricks, but in most cases it would be easily reversible.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Apr 2022 18:59:15 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dynatrace-Managed-Q-A/Credentials-are-transmitted-to-server-in-plain-text/m-p/185533#M1926</guid>
      <dc:creator>AntonioSousa</dc:creator>
      <dc:date>2022-04-26T18:59:15Z</dc:date>
    </item>
  </channel>
</rss>

