Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Penetration Testing
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: username and Password sent as clear text strings May 15 2008 02:35PM
Orlin Gueorguiev (orlin baturov com)
Hi John,
Well... you are not really sending the password in clear text.
Normally sending the password, be it encrypted or not, is thought to be an
vulnerability by itself, because if someone manages to break your encryption
(for example man in the middle as you suggested, or breaking the key, or
...

[ more ]  





 

Privacy Statement
Copyright 2008, SecurityFocus