1. #1
    skrtelfan
    skrtelfan's Avatar Become A Pro!
    Join Date: 10-09-08
    Posts: 1,913
    Betpoints: 3337

    BetPhoenix and password security

    Hopefully starting a new thread will bring some attention to this matter, but if anyone wasn't aware, BetPhoenix actually puts your password in the URL when you log in, and it's saved in your browser history. From a security standpoint, this is terrible, and may well explain why several people seem to be having problems with the security of their BP accounts. Until they rectify this matter, if you use BP, make sure you clear your browser history very frequently.

  2. #2
    michael777
    michael777's Avatar Become A Pro!
    Join Date: 09-20-05
    Posts: 1,936
    Betpoints: 3128

    been several posts about this around the forums for quite some time now and betphoenix has done nothing about it

  3. #3
    Thremp
    Thremp's Avatar Become A Pro!
    Join Date: 07-23-07
    Posts: 2,067

    TomCowley has mentioned this ad nauseum. Its ridiculous BP is managed/designed by such epic morons that somehow think this is a good idea.

  4. #4
    smitch124
    smitch124's Avatar SBR PRO
    Join Date: 05-19-08
    Posts: 12,564
    Betpoints: 1547

    What if you instruct the site not to "remember" you?, does the password still exist in the URL history? I will try this myself, but was just wondering if anyone knows offhand.

  5. #5
    skrtelfan
    skrtelfan's Avatar Become A Pro!
    Join Date: 10-09-08
    Posts: 1,913
    Betpoints: 3337

    I have the site not instructed to remember me and the password is still in my URL.

  6. #6
    WileOut
    WileOut's Avatar Become A Pro!
    Join Date: 02-04-07
    Posts: 3,844
    Betpoints: 54

    Simply go to tools and clear history every time you close Firefox. I did this anyway without even knowing about this little matter. Guys the same stuff is brought up about this book over and over. Its nit picking, if something arises out of it, it is solved that same day by BP's wonderful staff, and the book gives the best bonuses in the industry. Let it go. BetPhoenix is here to stay.

  7. #7
    Thremp
    Thremp's Avatar Become A Pro!
    Join Date: 07-23-07
    Posts: 2,067

    Quote Originally Posted by wileout View Post
    simply go to tools and clear history every time you close firefox. I did this anyway without even knowing about this little matter. Guys the same stuff is brought up about this book over and over. Its nit picking, if something arises out of it, it is solved that same day by bp's wonderful staff, and the book gives the best bonuses in the industry. Let it go. Betphoenix is here to stay.
    mai roflcopter goes soi soi soi soisoisosisoisosiosisosisoisoisois

  8. #8
    WileOut
    WileOut's Avatar Become A Pro!
    Join Date: 02-04-07
    Posts: 3,844
    Betpoints: 54

    lol thremp I'm trying to boost moral here.

  9. #9
    BigdaddyQH
    BigdaddyQH
    BigdaddyQH's Avatar Become A Pro!
    Join Date: 07-13-09
    Posts: 19,530
    Betpoints: 8638

    Problems like these are going to get worse, not better. Hackers are getting more and more sophisticated every day, and it is impossible for gaming sites to keep up. You will have to be very diligent.

  10. #10
    Jaug
    1 in 2.7 mill
    Jaug's Avatar Become A Pro!
    Join Date: 01-11-09
    Posts: 3,086
    Betpoints: 2977

    My password is certainly not in the url.

  11. #11
    smitch124
    smitch124's Avatar SBR PRO
    Join Date: 05-19-08
    Posts: 12,564
    Betpoints: 1547

    Quote Originally Posted by Jaug View Post
    My password is certainly not in the url.
    Did you view the URL in your browser history?

  12. #12
    BigDaddy
    BigDaddy's Avatar Become A Pro!
    Join Date: 02-01-06
    Posts: 8,378
    Betpoints: 729

    yes it is and that is just another red flag about this book


    WTF!

    that is unreal i just noticed it and never noticed it before

    thank you for this thread sktrelfan

  13. #13
    bluefish
    Update your status
    bluefish's Avatar Become A Pro!
    Join Date: 04-13-09
    Posts: 917

    not good

  14. #14
    Dark Horse
    Deus Ex Machina
    Dark Horse's Avatar Become A Pro!
    Join Date: 12-14-05
    Posts: 13,764

    I don't see the password in my URL.

  15. #15
    Thremp
    Thremp's Avatar Become A Pro!
    Join Date: 07-23-07
    Posts: 2,067

    Quote Originally Posted by Jaug View Post
    My password is certainly not in the url.
    Quote Originally Posted by Dark Horse View Post
    I don't see the password in my URL.
    lol

  16. #16
    skrtelfan
    skrtelfan's Avatar Become A Pro!
    Join Date: 10-09-08
    Posts: 1,913
    Betpoints: 3337

    Look carefully--log into your BetPhoenix account and watch the URL window. As you log in, your password will appear at the end of the URL, on the right hand side, then disappear. Depending on how fast your internet connection is, the password may only be on the screen for 1/4th of a second. But the password is still being transmitted via a URL, which is not very secure, and will also be saved in your browsing history.

  17. #17
    jogumon
    jogumon's Avatar Become A Pro!
    Join Date: 07-12-09
    Posts: 52

    It seems that if you log in to the old version, it does this. If you log in to the new site, it doesn't.

  18. #18
    xxxvince
    xxxvince's Avatar Become A Pro!
    Join Date: 12-17-07
    Posts: 2,567
    Betpoints: 156

    so old version ppl can hack? wtf

  19. #19
    Doug
    Doug's Avatar Become A Pro!
    Join Date: 08-10-05
    Posts: 6,324
    Betpoints: 1298

    good to know

  20. #20
    Dark Horse
    Deus Ex Machina
    Dark Horse's Avatar Become A Pro!
    Join Date: 12-14-05
    Posts: 13,764

    Quote Originally Posted by skrtelfan View Post
    Look carefully--log into your BetPhoenix account and watch the URL window. As you log in, your password will appear at the end of the URL, on the right hand side, then disappear. Depending on how fast your internet connection is, the password may only be on the screen for 1/4th of a second. But the password is still being transmitted via a URL, which is not very secure, and will also be saved in your browsing history.
    No. Nothing at all.

    Old version.

  21. #21
    THEGREAT30
    A man in need is a man exposed
    THEGREAT30's Avatar Become A Pro!
    Join Date: 10-04-08
    Posts: 8,970

    Quote Originally Posted by WileOut View Post
    Simply go to tools and clear history every time you close Firefox. I did this anyway without even knowing about this little matter. Guys the same stuff is brought up about this book over and over. Its nit picking, if something arises out of it, it is solved that same day by BP's wonderful staff, and the book gives the best bonuses in the industry. Let it go. BetPhoenix is here to stay.
    Nit picking does not need to take place when there is something new everyday

  22. #22
    skrtelfan
    skrtelfan's Avatar Become A Pro!
    Join Date: 10-09-08
    Posts: 1,913
    Betpoints: 3337

    Well, if you're using the old version and not seeing your password in the URL for a very brief period of time, either it's flashing by too fast for you to see it or they somehow have different accounts configured different ways. When I log in to the old version a URL of:

    URL: http://bettor1.betphoenix.com/custom/LoginVerify.asp?method=loginPost&langCode=en&customerID=XXXXX&password=XXXXXXXXX

    flashes by, with my user ID and password in place of the Xs. Then very shortly after (probably 1/4th of a second at most, probably depends on the speed of your computer) the URL switches to:

    http://bettor1.betphoenix.com/WagerMenu.asp

    I suppose the easy solution is "switch to the new version" but I find the new version significantly more difficult to navigate, particularly when there are a lot of games on the screen.
    Last edited by skrtelfan; 02-11-10 at 12:01 PM.

  23. #23
    Thremp
    Thremp's Avatar Become A Pro!
    Join Date: 07-23-07
    Posts: 2,067

    Claiming you can't see it in this case is akin to just closing your eyes and saying, "I don't believe in ghosts" three times. A cursory amount of effort would yield boundless results.

  24. #24
    20Four7
    Timmy T = Failure
    20Four7's Avatar Become A Pro!
    Join Date: 04-08-07
    Posts: 6,703
    Betpoints: 4120

    Quote Originally Posted by Dark Horse View Post
    I don't see the password in my URL.
    Neither do I dark, but I did a log in and watched the URL I very briefly got a password= xxxxxxx n the URL but it didn't show in my history. I use chrome by the way.

    Just did the old version and it clearly shows in the url for maybe 1/2 a second.

    URL: bettor1.betphoenix.com/custom/LoginVerify.asp?method=loginPost&langCode=en&customerID=Pxxxxxxx&password=xxxxxxxxxx

    old version saved in my history.
    Last edited by 20Four7; 02-11-10 at 04:39 AM.

  25. #25
    Jaug
    1 in 2.7 mill
    Jaug's Avatar Become A Pro!
    Join Date: 01-11-09
    Posts: 3,086
    Betpoints: 2977

    Yes that is really sick. Why the hell would my password be in browser url?

    Going to change password at phoenix, or better yet might just dump the site overall. They already took away reduced juice.

  26. #26
    SpreadSniper
    SpreadSniper's Avatar Become A Pro!
    Join Date: 02-17-09
    Posts: 6,125
    Betpoints: 7261

    the whole ****ing place seems like a joke.... slapped together by some Costa Rican with a commodore 64.... have you got one of their calls regarding their awsome "reload bonuses"?? Get the rep to explain the ENTIRE reload bonus process to you... If he/she can tell you the entire thing without messing up, or confusing themselves then they should be a politician.

  27. #27
    Dark Horse
    Deus Ex Machina
    Dark Horse's Avatar Become A Pro!
    Join Date: 12-14-05
    Posts: 13,764

    Quote Originally Posted by Thremp View Post
    Claiming you can't see it in this case is akin to just closing your eyes and saying, "I don't believe in ghosts" three times. A cursory amount of effort would yield boundless results.
    Why would you presume to know what I see? I told you I didn't see it and I didn't. The reason for that, after experimenting a little, is that I either log out or let the site log me out. On the old version. I never go back to the main menu, but log back in through the window where you log back in. The password never shows there. Guaranteed. That's also the window saved on my computer, so I never had the problem.

    Apparently, the new version doesn't show the password either.

    So the problem, while certainly undesirable, is very easily circumvented. But instead of focusing on the solution, the wave of newbie crybabies here is so stuck in their one-dimensional complaining that they fail to realize they're free to move on.

  28. #28
    durito
    escarabajo negro
    durito's Avatar Become A Pro!
    Join Date: 07-03-06
    Posts: 13,173
    Betpoints: 438

    Dark Horse is correct.

    If you log in here: http://bettor1.betphoenix.com/login.asp

    It does not happen and takes you to the old site.

    If you log in at betphoenix.com to the old site, it most certainly happens.

    So the problem, while certainly undesirable, is very easily circumvented. But instead of focusing on the solution, the wave of newbie crybabies here is so stuck in their one-dimensional complaining that they fail to realize they're free to move on.
    That's not really the point though. It is beyond horrid on their part and it was brought to their attention months ago. It never should have happened in the first place let alone not been fixed.

  29. #29
    Boscoe
    Boscoe's Avatar Become A Pro!
    Join Date: 02-08-10
    Posts: 2,811
    Betpoints: 494

    it's amazing how poorly designed the websites for even the most reputable sportsbooks can be. it's as if they were done for some junior high computer class. password in the url? unreal.....

  30. #30
    Dark Horse
    Deus Ex Machina
    Dark Horse's Avatar Become A Pro!
    Join Date: 12-14-05
    Posts: 13,764

    Quote Originally Posted by durito View Post
    It is beyond horrid on their part and it was brought to their attention months ago. It never should have happened in the first place let alone not been fixed.
    Yes, they should solve this asap. In the meantime, I prefer not to squeal like some victim, when the solution is so easily available.

  31. #31
    durito
    escarabajo negro
    durito's Avatar Become A Pro!
    Join Date: 07-03-06
    Posts: 13,173
    Betpoints: 438

    Quote Originally Posted by Dark Horse View Post
    Yes, they should solve this asap. In the meantime, I prefer not to squeal like some victim, when the solution is so easily available.
    For those of us that are aware of the problem and understand it. What is it that, maybe 1% of their players.

    How many more log in somewhere unsecured everyday with the possibility of having their account information stolen. And now all these reports of money disappearing from accounts.

    They allegedly have lots of money, how about spending $12 an hour on someone competent.

  32. #32
    Thremp
    Thremp's Avatar Become A Pro!
    Join Date: 07-23-07
    Posts: 2,067

    SBR too busy hugging their nuts to curr.

  33. #33
    Dark Horse
    Deus Ex Machina
    Dark Horse's Avatar Become A Pro!
    Join Date: 12-14-05
    Posts: 13,764

    Quote Originally Posted by durito View Post
    For those of us that are aware of the problem and understand it. What is it that, maybe 1% of their players.

    How many more log in somewhere unsecured everyday with the possibility of having their account information stolen. And now all these reports of money disappearing from accounts.

    They allegedly have lots of money, how about spending $12 an hour on someone competent.
    Agreed. It's a pity that we don't have a better understanding of what is going on at BP at the management level. In the old days SBR would keep us more or less updated, but nowadays they say nothing, either because they don't know or don't care.

    Meanwhile, without SBR directing traffic, but with a dramatic increase in, mostly uninformed, traffic, this forum has changed into its own variety of the sorcerer's apprentice. I used to come here for information on the industry. Now it's mostly nonsense by a bunch of sheep, bleating because the others are bleating.

    What they don't seem to understand is that it becomes much more challenging to hold books accountable, through legitimate complaints here, when an avalanche of unfounded complaints, that are not recognized as such by the readers here, makes it all but pointless to reply and react to valid complaints.

  34. #34
    skrtelfan
    skrtelfan's Avatar Become A Pro!
    Join Date: 10-09-08
    Posts: 1,913
    Betpoints: 3337

    Quote Originally Posted by Dark Horse View Post
    Why would you presume to know what I see? I told you I didn't see it and I didn't. The reason for that, after experimenting a little, is that I either log out or let the site log me out. On the old version. I never go back to the main menu, but log back in through the window where you log back in. The password never shows there. Guaranteed. That's also the window saved on my computer, so I never had the problem.

    Apparently, the new version doesn't show the password either.

    So the problem, while certainly undesirable, is very easily circumvented. But instead of focusing on the solution, the wave of newbie crybabies here is so stuck in their one-dimensional complaining that they fail to realize they're free to move on.
    Wow, you're a real idiot. First of all, an act as simple as logging into a sportsbook shouldn't need to be "easily circumvented," and the fact that BP can't figure out how to keep the password out of a URL is a legitimate problem. The onus shouldn't be on me to have to figure out how to keep my password out of the URL without "a little experimenting," and how do you "log back in" without logging in initially and having it display your password in the URL? I see that Durito posted a link to a log-in screen where you can log in without having the password displayed--how was I supposed to know to log-in to that page directly? I think I used BP for a couple months before I even noticed my password was in the URL, since it flashes by so quickly.

    I've been betting online since 1996 so it's foolishly presumptuous on your part to assume I'm a "crybaby newbie." Just today one moron on this board said it was inappropriate that I complained that BP call me as early as 715am, and now you're claiming the onus should be on me to figure out how to correct BP's account security. I guess you guys are right, I shouldn't mind getting woken up by them early in the morning and shouldn't be concerned about the security of my account.

  35. #35
    soxwin1917
    soxwin1917's Avatar Become A Pro!
    Join Date: 09-09-08
    Posts: 1,188
    Betpoints: 1922

    Quote Originally Posted by durito View Post
    For those of us that are aware of the problem and understand it. What is it that, maybe 1% of their players.

    How many more log in somewhere unsecured everyday with the possibility of having their account information stolen. And now all these reports of money disappearing from accounts.

    They allegedly have lots of money, how about spending $12 an hour on someone competent.
    Well said.

12 Last
Top