Re: Neomail security

<[email protected]> Mon, 29 Nov 2004 18:10:43 +0100
Newsgroups gmane.mail.neomail.general
Message-ID <011b01c4d636$602b3940$c5b12250@NODOCASA>
If yout read a message the resend of login data ocurs after push the back
button twice or more. As you say the page of login is always in browser
history.
And this is not a bug, others program has the same behavior, but in other
protected pages the behavior is right and if you back you reach a login page
(without resend data). So there must be a method to autenticate users
without this "fail".
And of course the most secure method is to close the browser, but not all
users are secure users : (
In this sense the logout could call a javascript to close the page, but this
is not infallible.

I'll go on investigating

Thanks





----- Original Message ----- 
From: "Ernie Miller" <[email protected]>
To: <[email protected]>; <[email protected]>
Sent: Monday, November 29, 2004 5:29 PM
Subject: Re: [Neomail-users] Neomail security


> This only happens on the very first page viewed after login -- this is
> because your browser resends the login and password.  If you click to view
a
> message and then log out, or perform any other action, then when you
logout
> your session is deleted.  As with all web based authentication mechanisms,
> it's always best to close the browser to be safe after a logout. There
will
> always be a page in the browser history that was generated by sending your
> login and pass and if a user is able to go back to it they will get in.
>
> To confirm this is the case note that the "bug" you mention results in you
> being assigned a new session id, which is viewable in the URL of the pages
> returned.
>
> ----- Original Message ----- 
> From: <[email protected]>
> To: <[email protected]>
> Sent: Monday, November 29, 2004 11:18 AM
> Subject: [Neomail-users] Neomail security
>
>
> In neomail th logout is not a real logout.
> Try to login in neomail, and then make logout. You are sent to the login
> screen, but if you puch back button on explorer you'll get the message of
> page expired, then you update the page and you are inside neomail again,
but
> you have not write yout login pass again!!!.
> So, if anybody logout from neomail and leave the computer on (with the
> explorer open), another person could enter in his neomail account using
the
> pages stored in history of browser.
>
> I think neomail would have to accept the login from a refreshed expired
> page. The only way I've found is add a "time mark" in the login form and
> compare this time mark with a time mark calculated in the moment of login,
> if the difference is a few seconds the login is processed, but if the
> difference is too high the login is not processed. But there is a problem,
> if the user delays too time writing his login data the login is rejected
> too.
>
> Regards
>
>




-------------------------------------------------------
SF email is sponsored by - The IT Product Guide
Read honest & candid reviews on hundreds of IT Products from real users.
Discover which products truly live up to the hype. Start reading now. 
http://productguide.itmanagersjournal.com/