Re: Neomail security

"Ernie Miller" <[email protected]> Mon, 29 Nov 2004 12:27:29 -0500
Newsgroups gmane.mail.neomail.general
Message-ID <007c01c4d638$b4629a10$b49e5d3f@Neo2>
Give an example of another program that is capable of overriding this 
browser-side behavior. The only scenario I could imagine is where there is 
an auto-redirect after login.  Even then, however, this is security through 
obscurity as if the user is fast enough they could refresh the page after 
clicking back to the auto-redirect page.

----- Original Message ----- 
From: <[email protected]>
To: <[email protected]>
Sent: Monday, November 29, 2004 12:10 PM
Subject: Re: [Neomail-users] Neomail security


> If yout read a message the resend of login data ocurs after push the back
> button twice or more. As you say the page of login is always in browser
> history.
> And this is not a bug, others program has the same behavior, but in other
> protected pages the behavior is right and if you back you reach a login 
> page
> (without resend data). So there must be a method to autenticate users
> without this "fail".
> And of course the most secure method is to close the browser, but not all
> users are secure users : (
> In this sense the logout could call a javascript to close the page, but 
> this
> is not infallible.
>
> I'll go on investigating
>
> Thanks
>
>
>
>
>
> ----- Original Message ----- 
> From: "Ernie Miller" <[email protected]>
> To: <[email protected]>; <[email protected]>
> Sent: Monday, November 29, 2004 5:29 PM
> Subject: Re: [Neomail-users] Neomail security
>
>
>> This only happens on the very first page viewed after login -- this is
>> because your browser resends the login and password.  If you click to 
>> view
> a
>> message and then log out, or perform any other action, then when you
> logout
>> your session is deleted.  As with all web based authentication 
>> mechanisms,
>> it's always best to close the browser to be safe after a logout. There
> will
>> always be a page in the browser history that was generated by sending 
>> your
>> login and pass and if a user is able to go back to it they will get in.
>>
>> To confirm this is the case note that the "bug" you mention results in 
>> you
>> being assigned a new session id, which is viewable in the URL of the 
>> pages
>> returned.
>>
>> ----- Original Message ----- 
>> From: <[email protected]>
>> To: <[email protected]>
>> Sent: Monday, November 29, 2004 11:18 AM
>> Subject: [Neomail-users] Neomail security
>>
>>
>> In neomail th logout is not a real logout.
>> Try to login in neomail, and then make logout. You are sent to the login
>> screen, but if you puch back button on explorer you'll get the message of
>> page expired, then you update the page and you are inside neomail again,
> but
>> you have not write yout login pass again!!!.
>> So, if anybody logout from neomail and leave the computer on (with the
>> explorer open), another person could enter in his neomail account using
> the
>> pages stored in history of browser.
>>
>> I think neomail would have to accept the login from a refreshed expired
>> page. The only way I've found is add a "time mark" in the login form and
>> compare this time mark with a time mark calculated in the moment of 
>> login,
>> if the difference is a few seconds the login is processed, but if the
>> difference is too high the login is not processed. But there is a 
>> problem,
>> if the user delays too time writing his login data the login is rejected
>> too.
>>
>> Regards
>>
>>
>
>
>
>
> -------------------------------------------------------
> SF email is sponsored by - The IT Product Guide
> Read honest & candid reviews on hundreds of IT Products from real users.
> Discover which products truly live up to the hype. Start reading now.
> http://productguide.itmanagersjournal.com/
> _______________________________________________
> NeoMail-users mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/neomail-users
> 



-------------------------------------------------------
SF email is sponsored by - The IT Product Guide
Read honest & candid reviews on hundreds of IT Products from real users.
Discover which products truly live up to the hype. Start reading now. 
http://productguide.itmanagersjournal.com/