WebApp Sec mailing list archives

FW: ASP authentication


From: "Rishi Pande" <rpande () vt edu>
Date: Fri, 27 Aug 2004 17:27:21 -0400



Don't know how heavy weight you want your solution to be but you may want to
look at the WEB-ISO products on http://middleware.internet2.edu
I personally like Authportal and CAS though all the solutions there are well
supported. 

        R


-----Original Message-----
From: BĂ©noni MARTIN [mailto:Benoni.MARTIN () libertis ga] 
Sent: Thursday, August 26, 2004 1:50 PM
To: webappsec () lists securityfocus com
Subject: ASP authentication

Hi List,

I am wondering what was the most secure way to allow users to access pages
after authentication, i.e.: user authenticates in toto.asp, and after that,
access is granted to tata_1.asp, tata_2.asp, ..., tata_n.asp. The trouble is
obviously to ask the user once for his login / password (just in tot.asp),
and to allow him to get to the other pages without asking each time his
credentials.

Googling around, I saw a couple of ways to meet my needs, but all seem to be
weak:
- I can set a hidden field where I can say "yes, he is authenticated" or
"no, he is not", but anyone a little bit skilled can create a fake request
having this set up by hand (with a proxy ! ),
- I can check a session number or smth like that on each page...but this
does not seem very reliable,
- I can check IP adress...but when you use AOL for instance, IP adresses can
change !

So none of the ways I found seem to be the best... 
 
Cheers list, for any reply / clue !




Current thread: