Intrusion Detection Systems mailing list archives
Bookmark URL's that contain authentication arguements
From: ICoS () operamail com (ICoS)
Date: Sun, 19 Dec 1999 15:30:49 -0500
I am really in need of some expert advice. I dont know if this is the correct place for this particular question but perhaps someone would be kind enough to direct me to a more appropriate list if it isnt. I have just installed a web interface for a mailing list software program. There is an authentication screen (userid/passwd) for initial log in before getting further in. I set up the administrator passwd and went to some of the list configuration pages where I can execute commands and manipulate headers. Out of habit more than anything I bookmarked these pages. When I use these bookmarks I can get straight at the configuration pages, the url contains the userid in plain text and the password in encrypted form. Trouble is these seem to be passed to the cgi script and it authenticates me with them and gives me a supposedly 10 minute ticket to do what I want in there. I asked the software providers about this and was told that I was bookmarking pages I shouldnt bookmark. To me this seems to be insecure and almost buggy. Am I wrong? ICoS ------------------------------------------------------------ This e-mail has been sent to you courtesy of OperaMail, as a free service from Opera Software, makers of the award-winning Web Browser, Opera. Visit us at http://www.opera.com/ or our portal at: http://www.myopera.com/ Your free e-mail account is waiting at: http://www.operamail.com/ ------------------------------------------------------------
Current thread:
- Re: Jeff Johnson's CMM security model -- any pointers?, (continued)
- Re: Jeff Johnson's CMM security model -- any pointers? Jackie Chan (Dec 10)
- NFR Help Rodolfo Dias (Dec 14)
- Re: NFR Help Delores A. Quade (Dec 14)
- Re: NFR Help Marcus J. Ranum (Dec 14)
- Re: NFR Help Greg Shipley (Dec 14)
- Re: NFR Help Carric Dooley (Dec 15)
- NEW TO IDS kbashir () engro com (Dec 15)
- Web Trends Sec Analyzer Duke Imaizumi (Dec 16)
- RE: NEW TO IDS Bill Royds (Dec 16)
- ISS's RealSecure on UNIX Richters, Eriks (Dec 16)
- Bookmark URL's that contain authentication arguements ICoS (Dec 19)
- Jeff Johnson's CAMM work Gene Kim (Dec 20)
- If Tripwire could detect ........... Duke Imaizumi (Dec 23)
- SATAN Bram Shirani (Dec 23)
- Re: SATAN B Potter (Dec 24)
- Re: SATAN Jonas Eriksson (Dec 27)
- Re: SATAN Carric Dooley (Dec 24)
- [Fwd: "An idea, a project, a collaboration"] Philip S Holt / Security Engineering (Dec 22)
- [CFP] RAID 2000 (Recent Advances in Intrusion Detection) Herve DEBAR (Dec 22)
