PDA

View Full Version : This one weird trick allowed me to access ATF eForms!



HeavyDuty
03-02-2023, 01:23 PM
I’ve been having issues accessing ATF’s eForm website for about two years now. I could only do it with one of my two Windows laptops, and not with my MacBook Air, iPad or iPhone. I would get a wrong password error. Another issue was really poor performance on the ATF website with the laptop that I could use - a lot of disconnects and very slow performance.

I use Apple’s password manager for everything, even something like this where I will let it generate and store a strong password that I would use elsewhere.

I had mentioned this to JCN awhile back, and he recommended not using Apple for passwords on this site. I was able to get in, so I didn’t follow his advice.

Yesterday I needed to create a PIN so Capitol Armory could certify me for a purchase. I decided I would change the password at the same time to something I manually created, which I then stored in Apple’s password manager. Now I can get it with all my devices, including iPad, iPhone and MacBook.

JCN, I owe you one for this. I just wish I had listened to you sooner!

tl;dr: don’t let Apple generate your ATF eForm website password.

GyroF-16
03-02-2023, 02:11 PM
I’ve been having issues accessing ATF’s eForm website for about two years now. I could only do it with one of my two Windows laptops, and not with my MacBook Air, iPad or iPhone. I would get a wrong password error. Another issue was really poor performance on the ATF website with the laptop that I could use - a lot of disconnects and very slow performance.

I use Apple’s password manager for everything, even something like this where I will let it generate and store a strong password that I would use elsewhere.

I had mentioned this to JCN awhile back, and he recommended not using Apple for passwords on this site. I was able to get in, so I didn’t follow his advice.

Yesterday I needed to create a PIN so Capitol Armory could certify me for a purchase. I decided I would change the password at the same time to something I manually created, which I then stored in Apple’s password manager. Now I can get it with all my devices, including iPad, iPhone and MacBook.

JCN, I owe you one for this. I just wish I had listened to you sooner!

tl;dr: don’t let Apple generate your ATF eForm website password.


Or, alternatively, copy and paste the password from the list of Apple passwords, rather than having the iOS put it in for you.
I’ve had this issue on several websites, and have come up with the copy-paste as a workaround.

HeavyDuty
03-02-2023, 02:19 PM
Or, alternatively, copy and paste the password from the list of Apple passwords, rather than having the iOS put it in for you.
I’ve had this issue on several websites, and have come up with the copy-paste as a workaround.

That didn’t work in my case at all. I was having issues with several iterations of Apple generated passwords which I then typed into the Win machines, and I was consistently getting password errors on all except one. As soon as I created my own password, all the machines worked fine.

GyroF-16
03-02-2023, 02:26 PM
That didn’t work in my case at all. I was having issues with several iterations of Apple generated passwords which I then typed into the Win machines, and I was consistently getting password errors on all except one. As soon as I created my own password, all the machines worked fine.

That’s really interesting. To be more specific in my case, I never let the Apple Keychain password function generate passwords for me - I use an app called 1Password. But I let iOS save those passwords after I enter them. So you may be into something in that it’s the password makeup.

WobblyPossum
03-02-2023, 02:26 PM
Interesting. I save my eForms login info in Apple passwords but I didn’t have Apple generate the password. It logs in fine using the button that imports the info from Apple passwords. You might be on to something with the Apple generated strong passwords for this site.

LHS
03-02-2023, 02:49 PM
Might be some kind of encoding or other characters in there that the archaic reforms site can't process. I'm just waiting for someone to do a SQL injection on them, with a serial number like Little Bobby Tables

SeriousStudent
03-02-2023, 04:47 PM
Might be some kind of encoding or other characters in there that the archaic reforms site can't process. I'm just waiting for someone to do a SQL injection on them, with a serial number like Little Bobby Tables

Ah, XKCD - for those who speak fluent nerd. :)

https://external-content.duckduckgo.com/iu/?u=https%3A%2F%2Fqph.fs.quoracdn.net%2Fmain-qimg-f53a38dd9f3c5f69033e74c648bd739f&f=1&nofb=1&ipt=dcdbbf80c5f5e43ccf8cd5f84205b28da474ea25ff4229 d30ee962af257a1fdc&ipo=images

LHS
03-02-2023, 05:28 PM
Ah, XKCD - for those who speak fluent nerd. :)

https://external-content.duckduckgo.com/iu/?u=https%3A%2F%2Fqph.fs.quoracdn.net%2Fmain-qimg-f53a38dd9f3c5f69033e74c648bd739f&f=1&nofb=1&ipt=dcdbbf80c5f5e43ccf8cd5f84205b28da474ea25ff4229 d30ee962af257a1fdc&ipo=images

I knew you were a man of culture and taste.