RESOLVED: Security Issue Spotted - Mainstreet Affiliates Login

Mainstreet Affiliates

ultra100

Affiliate Guard Dog Member
Joined
Aug 26, 2009
Messages
57
Reaction score
13
Hi Mainstreet Affiliates Team,

I recently logged into my Mainstreet Affiliates account to check if there was any activity from the past traffic I had sent to you, and I noticed a pretty serious security issue. The username and password are being passed in the URL parameters (?afflogin=xxx&affPwd=xxx).

1757660371248.png



This is not only bad practice, but it also represents a serious security risk. Credentials can be stored in browser history and server logs. Login credentials should never be sent via URL parameters — instead, they should be transmitted securely via POST requests over HTTPS.

I just noticed this now, not sure how long it has been going on, but this clearly puts affiliates at risk — could you please check this with your dev team ASAP?

Just wanted to flag this for the community and the team, so everyone is aware and it can be addressed.
 

ultra100

Affiliate Guard Dog Member
Joined
Aug 26, 2009
Messages
57
Reaction score
13

Mainstreet Affiliates
INFO

  1. AGD Terms Certification
    Terms and Conditions
  2. Slow/Delayed Payments?
    No
  3. Have Retroactively Changed T&C's?
    No
  4. Have Negative Carryover?
    No
  5. High Roller Policy
    No
  6. Are Casino Earnings Bundled?
    No
  7. Missing Admin Fee
    No
  8. Ambiguous Termination Clause
    No
  9. T&C updates not emailed
    No

AGD REPRESENTATIVE

Affiliate Software

RTG

AGD AUDIT RESULTS

25% = 25%
30% = 30%
35% = 35%
40% = 40%
45% = 45%

More info

Featured resources

  • TraffKnights
    TraffKnights
    High-paying gambling affiliate program offering customizable deals
    • Guard Dog
    • Updated:
  • Nifty Stats
    Nifty Stats
    stats tracking, casino stats. casino stats tracking, gambling stats, casino tracking, stats remote
    • woltran
    • Updated:
  • Slots Launch
    Slots Launch
    Free Demo Games for Casino Affiliates
    • Guard Dog
    • Updated:
  • TrafficStars
    TrafficStars
    Self-Serve ad Network
    • Guard Dog
    • Updated:
  • StatsDrone
    AGD Approved StatsDrone
    iGaming Affiliate Program Stats Tracker
    • Guard Dog
    • Updated:
Top