Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Penetration Testing: Re: username and Password sent as clear text strings

Re: username and Password sent as clear text strings

From: arvind doraiswamy <arvind.doraiswamy_at_gmail.com>
Date: Wed, 21 May 2008 09:53:01 +0530

@Marvin: I was talking of a salted hash where not even the client
knows what salt is going to be used coz it will be a rand() function
which will get called. And no the server must not be allowed to accept
just a plain text password -- it rarely happens that way because it
will run the hash() over the Plain text and wont get what it wants.
You will need to send the hash which you now cannot predict because of
teh salt. Then again if the slat also gets captured as you say -- due
to a lack of https its game over. I never said this is a replacement
for HTTPS -- it is just defense in depth I am talking about.

Cheers
Arvind

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Top 5 Common Mistakes
in Securing Web Applications
Find out now! Get Webinar Recording and PPT Slides

www.cenzic.com/landing/securityfocus/hackinar
------------------------------------------------------------------------
Received on May 21 2008

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]