Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Mozilla cleartext credentials leak bug report to excuse myself (Re[2]: NTLM HTTP Authentication is insecure by design - a new writeup by Amit Klein) Jul 19 2005 08:10PM
3APA3A (3APA3A SECURITY NNOV RU)
Dear Amit Klein (AKsecurity),

--Tuesday, July 19, 2005, 10:22:59 PM, you wrote to 3APA3A (at) SECURITY.NNOV (dot) RU [email concealed]:

AKA> For example, no-one expects NTLM auth to protect data in transit.

Actually, it may with NTLM Session Security.

AKA> Few years ago Internet Explorer was patched to use NTLM...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus