Re: is this webpage secure?

From: Dr Balwinder Singh Dheema (bsd.sanspam_at_cto.homelinux-dot-net.no-spam.invalid)
Date: 11/29/05


Date: 29 Nov 2005 20:13:58 GMT

Proteus wrote:
> I am told by people in charge at the campus where I teach that this
login
> page is secure, that the form login info (username, password) is
secure
> when sent. But the browser page (Firefox, Mandriva Linux) info says
the
> page is not encrypted, not secure. Can someone clarify how such a
login
> page can securely transmit the login info? Link to login page is
below:
> http://www.lsc.edu/Online/VirtualCampusLogin.cfm
>
No, I don't think; you are sending clear text data via _http_ (port
80),
where as URL's for secure pages send encrypted data via _https_ (http
via ssl, port 443).

You can verify/confirm it by capturing data on port 80 and, or 443
with
help of tcpdump(8) and, or ethereal(1).

-- 
Dr Balwinder Singh Dheeman            Registered Linux User: #229709
CLLO (Chief Linux Learning Officer)   Machines: #168573, 170593,
259192
Anu's Linux@HOME                      Distros: Ubuntu, Fedora, Knoppix
More: http://anu.homelinux.net/~bsd/  Visit: http://counter.li.org/


Relevant Pages

  • Re: Help, my machine has been hacked
    ... > being used to perform port scans on a bank. ... > closed HTTP) ... > DSLReports and they all report that my machine is secure. ... > 4) Recommendations for a hardware firewall? ...
    (comp.os.linux.security)
  • Re: Basic password security question
    ... Look at the pages - they never post that form over HTTP - usually the login form posts to an HTTPS address.... ... You need SSL - and if you have it for the rest of your site, why not for you login page too? ... Developing More Secure Microsoft ASP.NET 2.0 Applications ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: From http:// to https://
    ... > I have a login page that is secured with SSL and other non secure pages ... As Server.Transefer or response.redirect takes http by default. ... > standard method to transefer pages from normal to SSL page and vice versa. ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: Is .NET Passport credential traffic secure?
    ... my point is that you must FIRST establish a secure connection to ... user instead of making the login page itself secured with SSL so the ... The "Sign In" page at eBay submits the form data ... HTTPS site: Allowing the site to generate the HTML content in the page ...
    (microsoft.public.security)
  • Help, my machine has been hacked
    ... PMfirewall, all ports closed except for SSH, HTTPS and HTTP (I've since ... I've run the port scans on the Sheilds Up site and the ones on ... DSLReports and they all report that my machine is secure. ... Apr 5 18:07:31 dreadnought kernel: device eth0 entered promiscuous mode ...
    (comp.os.linux.security)