Remote redirect https traffic into http... for known reason of course :) EDIT 2015-11: Still vulnerable