RE: [Full-Disclosure] http://www.chase.com/ vulnerability

gauntlet_at_nym.hush.com
Date: 05/28/04

  • Next message: dk: "Re: [Full-Disclosure] Breaking Laws Cisco's stolen code"
    To: "'Perry E. Metzger'" <perry@piermont.com>, <full-disclosure@lists.netsys.com>
    Date: Fri, 28 May 2004 15:24:16 -0400
    
    

    Many financial institutions do the same thing.

    www.americanexpress.com:

    Security is important to everyone!

    Please be assured that, although the home page itself does not have an
    "https" URL, the login component of this page is secure. When you enter your
    User ID and password, your information is transmitted via a secure
    environment, and once the login is complete, you will be redirected to our
    secure area.

    If you wish to speak further with a technical specialist, please feel free
    to contact American Express Online Services at 1-800-297-1234, 24 hours/7
    days. If you are outside the United States, please call collect at
    1-336-393-1111.

    ---------------

    Rob

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: dk: "Re: [Full-Disclosure] Breaking Laws Cisco's stolen code"

    Relevant Pages

    • Re: is http mail secure?
      ... Can't I create a cert without going to ... > then use https. ... > Properties of the Virtual Site, selecting the Security tab and clicking on ... >> lock at the bottom telling me it's secure. ...
      (microsoft.public.exchange.connectivity)
    • Re: Versioning system
      ... > In the context of the O.P.'s notion of security, Bitkeeper would, much ... > secure communications. ... In many cases it is very convenient to just have the SSH ... Also the key management with ssh and https are ...
      (comp.os.linux.development.apps)
    • How to disable this Internet Explorer security alert message??
      ... On our site when a user is redirected from a secure ... page to a non secure page they get a pop-up ... But I still get the security alert message. ...
      (microsoft.public.inetserver.iis.security)
    • Re: is http mail secure?
      ... get a cetificate for your server ... then use https. ... If you don't, nothing is encrypted (unless you use integrated security, then ... > lock at the bottom telling me it's secure. ...
      (microsoft.public.exchange.connectivity)
    • Re: Ten least secure programs
      ... it's probably better you leave the topic alone ... I said I do not have security issues with the programs I code. ... I didn't realize you were a Linux user, ... > the most widely used and secure UNIX flavors? ...
      (Security-Basics)