WebApp Sec mailing list archives

RE: Should login pages be protected by SSL?


From: Simon Zuckerbraun <szucker () sst-pr-1 com>
Date: Sun, 26 Jun 2005 01:11:31 -0500

Saqib,

Could you explain for me what the insecurity is in REFRESH meta tags?

Many thanks,
Simon

Using REFRESH Meta tags, are very unsecure practice, for obvious
reasons. Redirects to HTTPS should always be performed using URL
REWRITEs on the server side.


Current thread: