Digest Password

From: azol (azol_at_discussions.microsoft.com)
Date: 06/27/05


Date: Mon, 27 Jun 2005 12:26:03 -0700

To authenticate a user, we can use a username and a password. It is
recommended to use a hashed password. We can make a digest password in the
client side or in the server side and compare it with the stored hashed
password in the database.

Why do we do this?
Let's say we pass the password in the clear text format and hash it in the
server side. In this case the hacker can monitor the network and get access
to the username and the password (before hashing process), then login to the
system with those credentials.

Now let's say that we hash the password in the client side and pass it to
the server. Also in this case, if a hacker monitors the and get access to the
username and the digested password, when it is getting transferred from the
client to the server, the hacker can use these credentials and login to the
system as well.

I would appreciate your clarifications.



Relevant Pages

  • RE: No Outlook Email via RDP
    ... Ensure you join the Terminal Server to SBS domain. ... input one SBS domain user's username and password ... | the Wyse Win Terminals accessing email via RDP. ...
    (microsoft.public.windows.server.sbs)
  • Re: cant use IMAP
    ... username and password again and again when you try to connect Exchange thru ... Please enable SSL IMAP on Exchange thru the following page. ... How to configure Outlook to receive e-mail messages from an IMAP server ... Microsoft CSS Online Newsgroup Support ...
    (microsoft.public.windows.server.sbs)
  • Re: mobile 6 cant access shares
    ... Let me ask you this...on the SBS how is it showing you accessing the shares? ... In open files what username is it saying is accessing the files? ... The event viewer on the server though shows a successful login. ... SBS showed a user Guest as being connected. ...
    (microsoft.public.pocketpc.phone_edition)
  • SOAP Client Authorization (Was: Re: IMAP server security vulnerability)
    ... username / RPC Security Interceptor" folks must be feelin' pretty ... No login reqd for Bank Account management? ... given server is to provided are clearly defined and rigidly enforced; ... I don't think I know a public web service that uses WS-S. ...
    (comp.os.vms)
  • Re: Accessing corporate servers through the web..
    ... Username and Password for unprivileged user is captured ... Denial of Service (you lose the server for a while) ... and getting console access to your server (which is actually what terminal ... PGP / XML GATEWAY APPLIANCE ...
    (Security-Basics)