Full Disclosure mailing list archives

Re: HTTP AUTH BASIC monowall.


From: Simon Smith <simon () snosoft com>
Date: Thu, 16 Mar 2006 15:12:57 -0500

Sweet,
    Someone else thats helpful! Thanks man!

Gary E. Miller wrote:
Yo Simon!

On Thu, 16 Mar 2006, Simon Smith wrote:

    Encoding a username and password combination using base64 is not
secure, but, I understand why it is encoded in base64. Having said
that,
I am trying to discover/create an alternate method for authentication
that is secure even if the SSL pipe is compromised.

If you do not like HTTP AUTH in SSL then why not just step up to HTTP
AUTH DIGEST?

http://httpd.apache.org/docs/2.2/mod/mod_auth_digest.html

RGDS
GARY
---------------------------------------------------------------------------
Gary E. Miller Rellim 20340 Empire Blvd, Suite E-3, Bend, OR 97701
    gem () rellim com  Tel:+1(541)382-8588


-- 
Regards,
    Jackass



_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: