Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Firewalls
Https - Secure Site Apr 30 2008 10:02PM
amatachick gmail com (2 replies)
I have what may be a simple question. When logging into a website that doesn't use SSL (https) are your credentials traveling in clear text? I am under the impression that the only way to encrypt your login is if the original page is https.

So that is my first question, and if I am correct that leads to my next question...

Is there anyway to encrypt this transmission using something besides SSL?

The reason that I ask is that I have seen numerous sites which use http on their login page. To me that means it's not encrypted and I can't understand why anyone would allow their login page to be unencrypted.

Again, this may be pretty basic but I would really like to get some feedback from you all. Thanks!!

[ reply ]
Re: Https - Secure Site May 05 2008 03:13PM
mouss (mouss netoyen net)
Re: Https - Secure Site Apr 30 2008 11:43PM
Jon Kibler (Jon Kibler aset com)







 

Privacy Statement
Copyright 2007, SecurityFocus