Re: Getting round website authentication with Firefox

From: Shalom Carmel (shalom_at_venera.com)
Date: 07/27/05

  • Next message: Alexander L. Ivanchev: "Re: Peter Gutmann data deletion theaory?"
    To: <bugtraq@securityfocus.com>
    Date: Wed, 27 Jul 2005 22:27:48 +0300
    
    

    Actually, this is a "feature" of most if not all browsers, that have no way
    to logout of URLs protected
    by HTTP basic authentication.

    Try to completely close all browser instances between the two attempts and
    you will discover that
    firefox asks for a login in all cases.

    Shalom Carmel
    ----------------
    www.venera.com - Exposing iSeries insecurity

    ----- Original Message -----

    >Using firefox's "save target as" feature, you can get round web
    authentication.
    >
    >Make a password protected directory (with a video file inside) (using
    .htaccess and htpasswd),
    >check that it actully requires a login when you click the link to the video
    normally,
    >then create a hyperlink to the file, right click save as - oh snap, it
    doesn't ask for authentication.
    >
    >I've only tested it with a video file and Firefox 1.0.6.


  • Next message: Alexander L. Ivanchev: "Re: Peter Gutmann data deletion theaory?"

    Relevant Pages

    • Re: Anonymous and NTLM
      ... This is by design, browsers will always attempt to connect anonymously, and ... base on authentication challenge header receive from web server, ... > the lowest credentials needed to complete a given resource request. ...
      (microsoft.public.inetserver.iis.security)
    • Re: Safari cant handle non-anonymous type schemes
      ... If you are using Integrated Windows Authentication - only IE supports that ... (it is a proprietary Microsoft authentication system). ... Other browsers support Basic, and I believe newer browsers support Digest. ...
      (microsoft.public.inetserver.iis.security)
    • Re: Whether IE on Mac supports authenticaiton?
      ... The internal network here is using integrated authentication and we have a ... Mac setup for testing with several browsers. ... these settings on the server to enable/disable the type of authentication. ...
      (microsoft.public.mac.explorer)
    • Re: Upload Files onto a Remote Server
      ... >Are all users going to write to the remote server as one ... authentication where the ... >ABCUpload to upload to a remote server, ... With properly configured web browsers, ...
      (microsoft.public.inetserver.iis.security)
    • Re: Safari cant handle non-anonymous type schemes
      ... :> If you are using Integrated Windows Authentication - only IE supports ... :> Other browsers support Basic, and I believe newer browsers support ... :>: Mozilla reportedly does the same thing. ...
      (microsoft.public.inetserver.iis.security)