The hotspot password is transmitted in clear text which is not a good idea. All logons should use SSL
POST /?action=login HTTP/1.1
accept=true&token=iwojeret62&login=Login&location=http%3A%2F%2Fwww.apple.com%2FHTTP/1.1 302 Found
Thanks
POST /?action=login HTTP/1.1
accept=true&token=iwojeret62&login=Login&location=http%3A%2F%2Fwww.apple.com%2FHTTP/1.1 302 Found
If an attacker has found the MAC address of another user and spoofs it, he doesn't even need the credentials to login.
Sent from my iPhone using Astaro.org