lol thinking about passwords being sent in clear text...
a popular "ex-AVS" if you want to call it that, passes all usernames and passwords clear text in URL strings. I notifed these people months ago, and its clear they still don't have it fixed.
all these urls get put into your weblogs, so if you really, really want to know who it is, and have avs traffic, grep out the active avs programs and inspect your logs. Its quite clear.
security seems to lack on programs, and most dont seem to care..
