Re: Neomail security
"Ernie Miller" <[email protected]> Mon, 29 Nov 2004 12:27:29 -0500
| Newsgroups | gmane.mail.neomail.general |
|---|---|
| Message-ID | <007c01c4d638$b4629a10$b49e5d3f@Neo2> |
Give an example of another program that is capable of overriding this browser-side behavior. The only scenario I could imagine is where there is an auto-redirect after login. Even then, however, this is security through obscurity as if the user is fast enough they could refresh the page after clicking back to the auto-redirect page. ----- Original Message ----- From: <[email protected]> To: <[email protected]> Sent: Monday, November 29, 2004 12:10 PM Subject: Re: [Neomail-users] Neomail security > If yout read a message the resend of login data ocurs after push the back > button twice or more. As you say the page of login is always in browser > history. > And this is not a bug, others program has the same behavior, but in other > protected pages the behavior is right and if you back you reach a login > page > (without resend data). So there must be a method to autenticate users > without this "fail". > And of course the most secure method is to close the browser, but not all > users are secure users : ( > In this sense the logout could call a javascript to close the page, but > this > is not infallible. > > I'll go on investigating > > Thanks > > > > > > ----- Original Message ----- > From: "Ernie Miller" <[email protected]> > To: <[email protected]>; <[email protected]> > Sent: Monday, November 29, 2004 5:29 PM > Subject: Re: [Neomail-users] Neomail security > > >> This only happens on the very first page viewed after login -- this is >> because your browser resends the login and password. If you click to >> view > a >> message and then log out, or perform any other action, then when you > logout >> your session is deleted. As with all web based authentication >> mechanisms, >> it's always best to close the browser to be safe after a logout. There > will >> always be a page in the browser history that was generated by sending >> your >> login and pass and if a user is able to go back to it they will get in. >> >> To confirm this is the case note that the "bug" you mention results in >> you >> being assigned a new session id, which is viewable in the URL of the >> pages >> returned. >> >> ----- Original Message ----- >> From: <[email protected]> >> To: <[email protected]> >> Sent: Monday, November 29, 2004 11:18 AM >> Subject: [Neomail-users] Neomail security >> >> >> In neomail th logout is not a real logout. >> Try to login in neomail, and then make logout. You are sent to the login >> screen, but if you puch back button on explorer you'll get the message of >> page expired, then you update the page and you are inside neomail again, > but >> you have not write yout login pass again!!!. >> So, if anybody logout from neomail and leave the computer on (with the >> explorer open), another person could enter in his neomail account using > the >> pages stored in history of browser. >> >> I think neomail would have to accept the login from a refreshed expired >> page. The only way I've found is add a "time mark" in the login form and >> compare this time mark with a time mark calculated in the moment of >> login, >> if the difference is a few seconds the login is processed, but if the >> difference is too high the login is not processed. But there is a >> problem, >> if the user delays too time writing his login data the login is rejected >> too. >> >> Regards >> >> > > > > > ------------------------------------------------------- > SF email is sponsored by - The IT Product Guide > Read honest & candid reviews on hundreds of IT Products from real users. > Discover which products truly live up to the hype. Start reading now. > http://productguide.itmanagersjournal.com/ > _______________________________________________ > NeoMail-users mailing list > [email protected] > https://lists.sourceforge.net/lists/listinfo/neomail-users > ------------------------------------------------------- SF email is sponsored by - The IT Product Guide Read honest & candid reviews on hundreds of IT Products from real users. Discover which products truly live up to the hype. Start reading now. http://productguide.itmanagersjournal.com/