Skip to content

SSID & password sent unsecured #258

@pratikpanchal22

Description

@pratikpanchal22

Configuring the network from the captive portal sends the SSID and APPSK as a GET request to the server running on ESP unsecured. The SSID and APPSK are seen in the url:

http://192.168.4.1/wifisave?s=HomeWifi&p=homeWifi402754

This is a security flaw and allows the snoopers to hijack the WiFi credentials very easily.

What would be a feasible solution for that?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions