Bennett000
Active Member
Finally, that screenshot of the supposed drop box is bullshit. They didn't even try to mock it up to look like it was a secure page. That's the kind of shit you're supposed to see on unfuckwithable's blog.
Just because the site didn't use SSL doesn't mean it's not secure. All SSL does is encrypt your connection to the server. It has nothing to do with authentication, or authorization. They could easily be using digest authentication, which is only MD5, but in order to even get the hash you'd have to be in the middle. Given what I saw after a simple port scan last night, and Vice's report that over the course of a week the site was brute forced, it's reasonable to assume the host provider is lazy. It's entirely plausible they don't use SSL. Plus it would costs the hosts more CPU cycles, and they're apparently a free provider.
Ultimately though, you're right, ManuvSteele should be taken with a grain of salt.