Warn HN: zoneedit.com
https://news.ycombinator.com/item?id=2064531The new zoneedit.com site transmits login credentials in plain text. The login popup has a 'Secure Login' button, but this only misleads users into thinking their login credentials are secured when they are not.
From the packet: POST /proxy.php HTTP/1.1\r\n endpoint=Authentication.action&action=login&userName=hello&password=hacker+news