Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 14 Mar 2000 00:13:00 +0100
From:      "Leif Neland" <leifn@neland.dk>
To:        <freebsd-isp@FreeBSD.ORG>
Subject:   Is passwords send to auth webpages secure?
Message-ID:  <010f01bf8d42$efda91e0$0e00a8c0@neland.dk>

next in thread | raw e-mail | index | archive | help

I have set a squid proxy to use samba_auth (When somebody is trying to use the proxyserver, they are presented with a normal browser-popup, and are prompted for a login/password. This is their NT-login/passwd, and if they are allowed to read a file on the NT with this login/pwd, they are granted access to the squid proxy).

Now I have been asked if the passwords from browser to squid is sent in cleartext, so it can be sniffed?

If so, this is an argument to get swiches instead of hubs...

Leif




To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-isp" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?010f01bf8d42$efda91e0$0e00a8c0>