Internet Explorer SSL encoding

From: Jon Keeney (jon_keeney@itsolutionstx.com)
Date: 10/09/02


From: "Jon Keeney" <jon_keeney@itsolutionstx.com>
Date: Tue, 8 Oct 2002 16:28:46 -0700


I have a web page at an http address. On this web page, I
have a form that uses the post method to send a username
and password to a secure script using action="https://

A security company is telling my customer, a bank, that
the data sent sent is not encrypted and is not secure.

It is my understanding that there is communication between
IE and the https server before any data is sent and then
the data is encrypted. Is this correct.

I need a thorough discussion on why this is true or not
true because of Banking rules and regulations. I am
technically capable of understanding a well thought out
reply.

Thanks



Relevant Pages

  • Re: email spam
    ... "Ant" wrote in message ... >> They have encoded the URL, in an effort to get it through a scanner. ... > is sent with the http request and could confirm to the spammer that you ... is a username or username/password combination n the format: ...
    (alt.computer.security)
  • Re: Secure access to RPC over HTTPs
    ... >1) We would like some kind of additional authentication beside username + ... >to successfully configure RPC over HTTP + the require user certificate option ... I understand a setup with RSA Secure ID is out of the ... Is it possible to force the ISA ...
    (microsoft.public.exchange.admin)
  • Re: Can I do this with a firewall? nat with Password!
    ... Thanks, and yes the current system is username and password protected, the ... defence. ... this easily done in a firewall or should I put a NAT router behind it? ... home page as http but have a link or a redirection to https. ...
    (comp.security.firewalls)
  • Re: Automate screen scraping: How to programmically "push" a Login button on another web page?
    ... You'll have to use HttpWebRequest to do a HTTP POST passing values for the IDs of the username and password fields. ... I'd suggest downloading Fiddler to see the HTTP traffic and it'll make what's being passed over the HTTP protocol seem so much more clear. ...
    (microsoft.public.dotnet.framework)
  • Re: Bug in http package
    ... Are you sure it is supported by the http package itself? ... The server indicates that it needs username and password as part of a basic authentication with the following header: ... http::geturl does not refresh the header information in the second round. ...
    (comp.lang.tcl)