is this webpage secure?

is this webpage secure?

Secure Home | Search | About
 Computer Software Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
is this webpage secure? Proteus 11-29-2005
Posted by Rasta Robert on December 2, 2005, 10:16 am
If you were  Registered and logged in, you could reply and use other advanced thread options
> wrote:
>
>>wrote:
>>
>>>I am told by people in charge at the campus where I teach that this login
>>>page is secure, that the form login info (username, password) is secure
>>>when sent. But the browser page (Firefox, Mandriva Linux) info says the
>>>page is not encrypted, not secure. Can someone clarify how such a login
>>>page can securely transmit the login info? Link to login page is below:
>>>http://www.lsc.edu/Online/VirtualCampusLogin.cfm
>>
>>Some times the page has to be opened in a new window to see the actual
>>encrypted (SSL) page, but it all depends on how the set up is made, if
>>you open in a new window and you don't see the SSL, I wouldn't trust
>>it.
>
> Its badly designed as although it is secure, it does not look that way
> to the user.

Could https://lsc.ims.mnscu.edu/ be used as an alternative and would
that be safer?

--
<http://rr.www.cistron.nl/> -!- <http://www.rr.dds.nl/>

Posted by Unruh on December 1, 2005, 12:13 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

>wrote:

>>I am told by people in charge at the campus where I teach that this login
>>page is secure, that the form login info (username, password) is secure
>>when sent. But the browser page (Firefox, Mandriva Linux) info says the
>>page is not encrypted, not secure. Can someone clarify how such a login
>>page can securely transmit the login info? Link to login page is below:
>>http://www.lsc.edu/Online/VirtualCampusLogin.cfm

>Some times the page has to be opened in a new window to see the actual
>encrypted (SSL) page, but it all depends on how the set up is made, if
>you open in a new window and you don't see the SSL, I wouldn't trust
>it.

Here is the line
<tr>
<td align="right" bgcolor="#ffffff" bordercolor="#336666"
width="250"><form
action="https://lsc.ims.mnscu.edu/d2l/Tools/login/doLogin.asp"
method="post" name="processLogonForm"><br/><label
for="userName">Username:</label>&nbsp;&nbsp; <input id="userName"
name="userName" size="10"/> <br/><br/><label
for="password">Password:</label>&nbsp;&nbsp;&nbsp; <input id="password"
name="password" size="10" type="password"/> <br/><br/><input name="Login"
type="submit"/></form><div align="right"><p class="toplinks"><a
href="login.cfm">having problems?</a></p>

</div></td>
(all one line in the original). I do not know if the data gets sent to
that https://lsc.ims.mnscu.edu/d2l/Tools/login/doLogin.asp page before of after
https is invoked.


>Regards
>>


Posted by grenoble on December 1, 2005, 1:16 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

> Here is the line
> <tr>
> <td align="right" bgcolor="#ffffff" bordercolor="#336666"
> width="250"><form
> action="https://lsc.ims.mnscu.edu/d2l/Tools/login/doLogin.asp"
> method="post" name="processLogonForm"><br/><label
> for="userName">Username:</label>&nbsp;&nbsp; <input id="userName"
> name="userName" size="10"/> <br/><br/><label
> for="password">Password:</label>&nbsp;&nbsp;&nbsp; <input
> id="password"
> name="password" size="10" type="password"/> <br/><br/><input
> name="Login" type="submit"/></form><div align="right"><p
> class="toplinks"><a
> href="login.cfm">having problems?</a></p>
>
> </div></td>
> (all one line in the original). I do not know if the data gets sent
> to that https://lsc.ims.mnscu.edu/d2l/Tools/login/doLogin.asp
> page before of after https is invoked.

Ethereal shows quite plainly that the data are sent after the https (SSL) is
invoked, but the data are NOT (repeat NOT) encrypted. They are sent as clear
text userName/password to port 443 of the https server.


Posted by grenoble on December 1, 2005, 4:31 am
If you were  Registered and logged in, you could reply and use other advanced thread options

> Can someone clarify how such a login
> page can securely transmit the login info? Link to login page is below:
> http://www.lsc.edu/Online/VirtualCampusLogin.cfm

http://www.iss.net/security_center/reference/2110099.html results, and a
look at the ethereal capture at our router confirms that plain, unencrypted
text is transmitted over the SSL connection.


Posted by Winged on December 1, 2005, 8:04 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
grenoble wrote:
>
>
>>Can someone clarify how such a login
>>page can securely transmit the login info? Link to login page is below:
>>http://www.lsc.edu/Online/VirtualCampusLogin.cfm
>
>
> http://www.iss.net/security_center/reference/2110099.html results, and a
> look at the ethereal capture at our router confirms that plain, unencrypted
> text is transmitted over the SSL connection.
>
You mean i read the code and posted correctly then I apologized after
reading where someone hard used eretheal and said it was encrypted...
...thanks guys for looking harder than I did and confirming I was not as
far gone as I thought I was....seems pretty weak security on a campus
where kids seem to catch stuff easily..If I remember the page right it
was one of the purtiest formatted pages I have seen recently even if it
wasn't secure...

Winged

Similar ThreadsPosted
Advice needed on secure remote datacenter and secure communication August 24, 2008, 8:36 pm
Secure Auditor secure your windows April 28, 2008, 6:24 am
Does SSL "secure" WEP? October 13, 2006, 3:40 am
Which Is More Secure??? January 4, 2007, 7:47 pm
is my network secure? November 26, 2005, 11:52 pm
Secure passwords? November 30, 2005, 2:45 pm
Is my file secure? February 9, 2006, 4:33 pm
Secure web page? February 22, 2006, 4:16 pm
What's up with secure-tunnel.com May 13, 2006, 4:14 pm
Is Javascript Secure? June 7, 2006, 12:11 pm

The site map in XML format XML site map

Contact Us | Privacy Policy