Re: [users@httpd] SSL / HTML question

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On 2/6/06, Mark McCulligh <mmcculli@xxxxxxxxxxxxx> wrote:
> The client should alway be logging
> in on their website for I hope they reallize if they where not on their
> website.

I'm not sure if you understood or not, but my point was that a
man-in-the-middle could make it look exactly like they were on their
own site.  He could simply replace the target URL on the form to point
to his own site.  (If you checked the URL-bar, you might see
after-the-fact that you had gone to the wrong site.  But the data
would already be stolen.)

Joshua.

---------------------------------------------------------------------
The official User-To-User support forum of the Apache HTTP Server Project.
See <URL:http://httpd.apache.org/userslist.html> for more info.
To unsubscribe, e-mail: users-unsubscribe@xxxxxxxxxxxxxxxx
   "   from the digest: users-digest-unsubscribe@xxxxxxxxxxxxxxxx
For additional commands, e-mail: users-help@xxxxxxxxxxxxxxxx



[Index of Archives]     [Open SSH Users]     [Linux ACPI]     [Linux Kernel]     [Linux Laptop]     [Kernel Newbies]     [Security]     [Netfilter]     [Bugtraq]     [Squid]     [Yosemite News]     [MIPS Linux]     [ARM Linux]     [Linux Security]     [Linux RAID]     [Samba]     [Video 4 Linux]     [Device Mapper]

  Powered by Linux