Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 13 Mar 2000 23:43:15 -0600
From:      Chris Cook <ccook@tcworks.net>
To:        Leif Neland <leif@neland.dk>
Cc:        freebsd-isp@FreeBSD.ORG
Subject:   Re: Is passwords send to auth webpages secure?
Message-ID:  <38CDD173.EEB690BD@tcworks.net>
References:  <010f01bf8d42$efda91e0$0e00a8c0@neland.dk>

next in thread | previous in thread | raw e-mail | index | archive | help
Leif Neland wrote:
> 
> 
> Now I have been asked if the passwords from browser to squid is sent in cleartext, so it can be sniffed?

I have tried sniffing passwords like this before as a test, and they
always showed up as scrambled (unreadable).  I am assuming that my
browser (Netscape 4.6/FreeBSD) was using some sort of mild encryption to
send the username/login.  More info on this would be neat, but you
should invest in some switches anyways.  Hasto...

-- 
Chris

o----< ccook@tcworks.net >----------------------------------------o
|Chris Cook - Technician  |  TCWORKS.NET - http://www.tcworks.net |
|The Computer Works       |  FreeBSD - http://www.freebsd.org     |
o-----------------------------------------------------------------o


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-isp" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?38CDD173.EEB690BD>