Re: Neomail security
<[email protected]> Tue, 30 Nov 2004 17:02:32 +0100
| Newsgroups | gmane.mail.neomail.general |
|---|---|
| Message-ID | <006d01c4d6f6$0371b920$c5b12250@NODOCASA> |
The access to my dns service or my bank account are protected by a login/password and the back button doesn't resend my data, it send to a login page. I don't know how they do it. Google adsense, for instance, show this behavior: back button resend data. This is not a security bug of Neomail, and I don't know how to avoid it, that's the reason I've proposed this question. I think browsers shouldn't save any page with no-cache pragma in its history. It's absurd that, in expired page, the message say that it doesn't send data for security reasons and allow user refresh page to send this data. Illogical, I can see the security in browser. Regards ----- Original Message ----- From: "Ernie Miller" <[email protected]> To: <[email protected]>; <[email protected]> Sent: Monday, November 29, 2004 6:27 PM Subject: Re: [Neomail-users] Neomail security > Give an example of another program that is capable of overriding this > browser-side behavior. The only scenario I could imagine is where there is > an auto-redirect after login. Even then, however, this is security through > obscurity as if the user is fast enough they could refresh the page after > clicking back to the auto-redirect page. > > ----- Original Message ----- > From: <[email protected]> > To: <[email protected]> > Sent: Monday, November 29, 2004 12:10 PM > Subject: Re: [Neomail-users] Neomail security > > > > If yout read a message the resend of login data ocurs after push the back > > button twice or more. As you say the page of login is always in browser > > history. > > And this is not a bug, others program has the same behavior, but in other > > protected pages the behavior is right and if you back you reach a login > > page > > (without resend data). So there must be a method to autenticate users > > without this "fail". > > And of course the most secure method is to close the browser, but not all > > users are secure users : ( > > In this sense the logout could call a javascript to close the page, but > > this > > is not infallible. > > > > I'll go on investigating > > > > Thanks > > > > > > > > > > > > ----- Original Message ----- > > From: "Ernie Miller" <[email protected]> > > To: <[email protected]>; <[email protected]> > > Sent: Monday, November 29, 2004 5:29 PM > > Subject: Re: [Neomail-users] Neomail security > > > > > >> This only happens on the very first page viewed after login -- this is > >> because your browser resends the login and password. If you click to > >> view > > a > >> message and then log out, or perform any other action, then when you > > logout > >> your session is deleted. As with all web based authentication > >> mechanisms, > >> it's always best to close the browser to be safe after a logout. There > > will > >> always be a page in the browser history that was generated by sending > >> your > >> login and pass and if a user is able to go back to it they will get in. > >> > >> To confirm this is the case note that the "bug" you mention results in > >> you > >> being assigned a new session id, which is viewable in the URL of the > >> pages > >> returned. > >> > >> ----- Original Message ----- > >> From: <[email protected]> > >> To: <[email protected]> > >> Sent: Monday, November 29, 2004 11:18 AM > >> Subject: [Neomail-users] Neomail security > >> > >> > >> In neomail th logout is not a real logout. > >> Try to login in neomail, and then make logout. You are sent to the login > >> screen, but if you puch back button on explorer you'll get the message of > >> page expired, then you update the page and you are inside neomail again, > > but > >> you have not write yout login pass again!!!. > >> So, if anybody logout from neomail and leave the computer on (with the > >> explorer open), another person could enter in his neomail account using > > the > >> pages stored in history of browser. > >> > >> I think neomail would have to accept the login from a refreshed expired > >> page. The only way I've found is add a "time mark" in the login form and > >> compare this time mark with a time mark calculated in the moment of > >> login, > >> if the difference is a few seconds the login is processed, but if the > >> difference is too high the login is not processed. But there is a > >> problem, > >> if the user delays too time writing his login data the login is rejected > >> too. > >> > >> Regards > >> > >> > > > > > > > > > > ------------------------------------------------------- > > SF email is sponsored by - The IT Product Guide > > Read honest & candid reviews on hundreds of IT Products from real users. > > Discover which products truly live up to the hype. Start reading now. > > http://productguide.itmanagersjournal.com/ > > _______________________________________________ > > NeoMail-users mailing list > > [email protected] > > https://lists.sourceforge.net/lists/listinfo/neomail-users > > > > ------------------------------------------------------- SF email is sponsored by - The IT Product Guide Read honest & candid reviews on hundreds of IT Products from real users. Discover which products truly live up to the hype. Start reading now. http://productguide.itmanagersjournal.com/