开发者

How to submit login info securely from non-ssl wrapped page?

开发者 https://www.devze.com 2023-02-20 17:29 出处:网络
In my webpages that are not SSL wrapp开发者_C百科ed, I have a login form. Users can enter their username and password and submit the info in that login form to authenticate.

In my webpages that are not SSL wrapp开发者_C百科ed, I have a login form. Users can enter their username and password and submit the info in that login form to authenticate.

The action specified in the login form is https:///login. Is this enough for the into to be encrypted or do both pages have to be ssl wrapped?

Thanks Eric


It is enough.

This way, an attacker can not get the login user and password because the browser is sending them encrypted. BUT if after the login you revert to plain http, an attacker may sniff the session cookie and use that to impersonate your users. See firesheep for details.

0

精彩评论

暂无评论...
验证码 换一张
取 消

关注公众号