Proxy Sites

Miscellaneous Forums/General Discussion/Proxy Sites

I was wondering, if i were to use a proxy site to log into something like Myspace( which I dont have) would the proxy site have my name and password stored on their server?

Also, I have another post titled .scf, If anybody knows anything about that extention, please respond, I need help.

Any username/password will pass through the server, so technically they can see what you're sending.

Depending on the nature of the proxy and the site in question, another person going to the same URL might even automatically end up being logged in as you as well (if they're determining sessions based on IP address rather than cookies or something, since to the end-site the originating IP address will be the proxy, not your computer)

But even if the website in question doesn't mix up the sessions, there's still the issue that the proxy can see (and save) your username/password info should htey choose to do so. After all, it's traversing their server in plain text.

You're only (mostly) safe if the site uses HTTPS instead of HTTP, because the HTTPS link is encrypted end-to-end, and the proxy can't read the contents such as username/password info.

So would you advise doing something like that or not?

So would you advise doing something like that or not?


Depends entirely on how much you trust the operators of the proxy servers, and also how the site you're visiting manages their sessions.

It's nuts to submit any creditcard info through a remote proxy, that's for sure.

But to really answer your question: NO. Simply because the entire pretext of your question is whether or not it's save to use a proxy to access myspace, you're insinuating that the network you are on prohibits you from getting there. (I mean -- really -- there is little other explanation for this situation)
Using a proxy to circumvent such blocks would violate either the acceptable network use policies at your place of employment (which could lead to you getting fired for circumventing the block and 'abusing' their internet connection), or trying to get past a filter put in place by a parent/guardian, which you shouldn't be trying to get around either.

So... No. Bad idea all around.

alright lol

I run proxies. I imagine it wouldn't be too difficult to intercept login data, though I haven't really looked into it. If you want to use a proxy run by a member of the Blitz community, check out one of my sites at Divoxa.com .

In addition to normal http proxies, there are also https proxies which transfer information in a secure form. Whether this would prevent the operator from intercepting login data, I don't know. One https proxy that I know of is Proxify.com . You can find more listed at Proxy.org .

If you have access to shared webhosting or better with php support, you could set up your own proxy site. Visit the forums at Proxy.org to find scripts. Generally, you'll just need to upload the proxy script and you're good to go. Bear in mind that proxies use a lot of system resources, so if you set one up on shared hosting, make sure that it is not used by too many other people or your account will get shut down.

EDIT:

I found the info quoted below on the Surrogofier proxy script site at http://bcable.net/project.php?surrogafier .

DO NOT USE THIS PROXY AS OF NOW TO ACCESS ANY SENSITIVE INFORMATION, INCLUDING BUT NOT LIMITED TO CREDIT CARD INFORMATION, SOCIAL SECURITY NUMBERS, SENSITIVE PASSWORDS, AND OTHER SIMILAR THINGS! Currently, SSL/TLS is supported through just entering a URL in the field. BEWARE: This does NOT secure your connection to the proxy server as of yet, only the connection from the proxy server to the web server the request is going to! This might create a false sense of security for some people, as your passwords are being passed openly without encryption through the Internet.


sounds like giving someone your atm card and pin and asking them to go to the machine for you ;)

or telephone shopping with people in earshot of your card