Neomail security
<[email protected]> Mon, 29 Nov 2004 17:18:23 +0100
| Newsgroups | gmane.mail.neomail.general,gmane.spam.detected |
|---|---|
| Message-ID | <00ee01c4d62f$0fe4b3f0$c5b12250@NODOCASA> |
This is a multi-part message in MIME format. ------=_NextPart_000_00EB_01C4D637.6E826080 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable In neomail th logout is not a real logout. Try to login in neomail, and then make logout. You are sent to the login = screen, but if you puch back button on explorer you'll get the message = of page expired, then you update the page and you are inside neomail = again, but you have not write yout login pass again!!!. So, if anybody logout from neomail and leave the computer on (with the = explorer open), another person could enter in his neomail account using = the pages stored in history of browser.=20 I think neomail would have to accept the login from a refreshed expired = page. The only way I've found is add a "time mark" in the login form and = compare this time mark with a time mark calculated in the moment of = login, if the difference is a few seconds the login is processed, but if = the difference is too high the login is not processed. But there is a = problem, if the user delays too time writing his login data the login is = rejected too. Regards ------=_NextPart_000_00EB_01C4D637.6E826080 Content-Type: text/html; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <HTML><HEAD> <META http-equiv=3DContent-Type content=3D"text/html; = charset=3Diso-8859-1"> <META content=3D"MSHTML 6.00.2800.1476" name=3DGENERATOR> <STYLE></STYLE> </HEAD> <BODY bgColor=3D#ffffff> <DIV><FONT face=3DArial size=3D2> <DIV><FONT face=3DArial size=3D2>In neomail th logout is not a real=20 logout.</FONT></DIV> <DIV><FONT face=3DArial size=3D2>Try to login in neomail, and then make = logout. You=20 are sent to the login screen, but if you puch back button on explorer = you'll get=20 the message of page expired, then you update the page and you are inside = neomail=20 again, but you have not write yout login pass again!!!.</FONT></DIV> <DIV><FONT face=3DArial size=3D2>So, if anybody logout from neomail and = leave the=20 computer on (with the explorer open), another person could enter in his = neomail=20 account using the pages stored in history of browser. </FONT></DIV> <DIV><FONT face=3DArial size=3D2></FONT> </DIV> <DIV><FONT face=3DArial size=3D2>I think neomail would have to accept = the login from=20 a refreshed expired page. The only way I've found is add a "time mark" = in the=20 login form and compare this time mark with a time mark calculated in the = moment=20 of login, if the difference is a few seconds the login is processed, but = if the=20 difference is too high the login is not processed. But there is a = problem, if=20 the user delays too time writing his login data the login is rejected=20 too.</FONT></DIV> <DIV><FONT face=3DArial size=3D2></FONT> </DIV> <DIV><FONT face=3DArial = size=3D2>Regards</FONT></DIV></FONT></DIV></BODY></HTML> ------=_NextPart_000_00EB_01C4D637.6E826080-- ------------------------------------------------------- SF email is sponsored by - The IT Product Guide Read honest & candid reviews on hundreds of IT Products from real users. Discover which products truly live up to the hype. Start reading now. http://productguide.itmanagersjournal.com/