[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <42FA0040.21148.8BD02F8D@localhost>
Date: Wed Aug 10 02:25:30 2005
From: nick at virus-l.demon.co.uk (Nick FitzGerald)
Subject: Insecure http pages referencing https
form-actions.
fd@...nsci.us wrote:
> Today I realized that many "secured" web sites reference their secure
> login page from an insecure page. For example:
>
> http://www.some-luser.com/login.html:
> <form action="https://cgi.some-luser.com/login-cgi">
> user: <input name=user>
> pass: <input name=pass>
> </form>
Welcome to, ohhh, 1997???
I can't be bothered looking it up, but this is ancient.
Of course, that it still happens really, often, on huge sites that
really should know better says a lot about, well, many things really...
Regards,
Nick FitzGerald
Powered by blists - more mailing lists