Re: Neomail security

<[email protected]> Tue, 30 Nov 2004 17:02:32 +0100
Newsgroups gmane.mail.neomail.general
Message-ID <006d01c4d6f6$0371b920$c5b12250@NODOCASA>
The access to my dns service or my bank account are protected by a
login/password and the back button doesn't resend my data, it send to a
login page. I don't know how they do it. Google adsense, for instance, show
this behavior: back button resend data. This is not a security bug of
Neomail, and I don't know how to avoid it, that's the reason I've proposed
this question.
I think browsers shouldn't save any page with no-cache pragma in its
history. It's absurd that, in expired page, the message say that it doesn't
send data for security reasons and allow user refresh page to send this
data. Illogical, I can see the security in browser.
Regards

----- Original Message ----- 
From: "Ernie Miller" <[email protected]>
To: <[email protected]>; <[email protected]>
Sent: Monday, November 29, 2004 6:27 PM
Subject: Re: [Neomail-users] Neomail security


> Give an example of another program that is capable of overriding this
> browser-side behavior. The only scenario I could imagine is where there is
> an auto-redirect after login.  Even then, however, this is security
through
> obscurity as if the user is fast enough they could refresh the page after
> clicking back to the auto-redirect page.
>
> ----- Original Message ----- 
> From: <[email protected]>
> To: <[email protected]>
> Sent: Monday, November 29, 2004 12:10 PM
> Subject: Re: [Neomail-users] Neomail security
>
>
> > If yout read a message the resend of login data ocurs after push the
back
> > button twice or more. As you say the page of login is always in browser
> > history.
> > And this is not a bug, others program has the same behavior, but in
other
> > protected pages the behavior is right and if you back you reach a login
> > page
> > (without resend data). So there must be a method to autenticate users
> > without this "fail".
> > And of course the most secure method is to close the browser, but not
all
> > users are secure users : (
> > In this sense the logout could call a javascript to close the page, but
> > this
> > is not infallible.
> >
> > I'll go on investigating
> >
> > Thanks
> >
> >
> >
> >
> >
> > ----- Original Message ----- 
> > From: "Ernie Miller" <[email protected]>
> > To: <[email protected]>; <[email protected]>
> > Sent: Monday, November 29, 2004 5:29 PM
> > Subject: Re: [Neomail-users] Neomail security
> >
> >
> >> This only happens on the very first page viewed after login -- this is
> >> because your browser resends the login and password.  If you click to
> >> view
> > a
> >> message and then log out, or perform any other action, then when you
> > logout
> >> your session is deleted.  As with all web based authentication
> >> mechanisms,
> >> it's always best to close the browser to be safe after a logout. There
> > will
> >> always be a page in the browser history that was generated by sending
> >> your
> >> login and pass and if a user is able to go back to it they will get in.
> >>
> >> To confirm this is the case note that the "bug" you mention results in
> >> you
> >> being assigned a new session id, which is viewable in the URL of the
> >> pages
> >> returned.
> >>
> >> ----- Original Message ----- 
> >> From: <[email protected]>
> >> To: <[email protected]>
> >> Sent: Monday, November 29, 2004 11:18 AM
> >> Subject: [Neomail-users] Neomail security
> >>
> >>
> >> In neomail th logout is not a real logout.
> >> Try to login in neomail, and then make logout. You are sent to the
login
> >> screen, but if you puch back button on explorer you'll get the message
of
> >> page expired, then you update the page and you are inside neomail
again,
> > but
> >> you have not write yout login pass again!!!.
> >> So, if anybody logout from neomail and leave the computer on (with the
> >> explorer open), another person could enter in his neomail account using
> > the
> >> pages stored in history of browser.
> >>
> >> I think neomail would have to accept the login from a refreshed expired
> >> page. The only way I've found is add a "time mark" in the login form
and
> >> compare this time mark with a time mark calculated in the moment of
> >> login,
> >> if the difference is a few seconds the login is processed, but if the
> >> difference is too high the login is not processed. But there is a
> >> problem,
> >> if the user delays too time writing his login data the login is
rejected
> >> too.
> >>
> >> Regards
> >>
> >>
> >
> >
> >
> >
> > -------------------------------------------------------
> > SF email is sponsored by - The IT Product Guide
> > Read honest & candid reviews on hundreds of IT Products from real users.
> > Discover which products truly live up to the hype. Start reading now.
> > http://productguide.itmanagersjournal.com/
> > _______________________________________________
> > NeoMail-users mailing list
> > [email protected]
> > https://lists.sourceforge.net/lists/listinfo/neomail-users
> >
>
>




-------------------------------------------------------
SF email is sponsored by - The IT Product Guide
Read honest & candid reviews on hundreds of IT Products from real users.
Discover which products truly live up to the hype. Start reading now. 
http://productguide.itmanagersjournal.com/