Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




webappsec logo WebApp Sec mailing list archives

Re: Must we authenticate login forms (using SSL?)?
From: info () biledge com
Date: Thu, 29 Sep 2005 11:03:06 +0300

hi,

we do authenticate login forms with SSL or not, UAE (users  are everywhere) is
the valid one, the attack is unavoidable. kind of hit-and-hide game. then MITM is also = UITM.

if we can create a 'secure system' among all servers in the world, then we may provide
security. but if clauses are jokers sometimes, i think it is better to prefer the identity based 
security systems. you can have SSL but user may not use https. if servers can control the use 
of https, then i think things would be different in terms of security (now i feel very insecure !)..
i am just thinking though..

regards,

billur c.



  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]