4 ms·
actually "false, I checked that already. the iframe src is http://webtix1.sundance.org/webtixsnet/?key=RegPublic-PITW http://webtix1.sundance.org/webtixsnet/?k
by magic5227 14y ago
actually
"false, I checked that already. the iframe src is http://webtix1.sundance.org/webtixsnet/?key=RegPublic-PITW http://webtix1.sundance.org/webtixsnet/?key=RegPublic-PITW
the form's action is "OrderFormPage.aspx?dtticks=634878773966587077" which means that the form submits to http://webtix1.sundance.org/webtixsnet/OrderFormPage.aspx?dtticks=634878773966587077 http://webtix1.sundance.org/webtixsnet/OrderFormPage.aspx?dt...
so the iframe isn't ssl, and the form doesn't submit to an SSL page either.
furthermore! even if the iframe were over ssl (which it isn't), that still wouldn't be secure. since the outer page isn't over ssl, an attacker could replace the iframe with one that has the same content but points to a non-ssl page. this is why SSL is useless unless the user checks the browser SSL indicator (the green lock in the URL bar)."