lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Date: Fri, 8 Sep 2006 15:51:08 +0100
From: "Richard Braganza" <iwtb0202@...glemail.com>
To: full-disclosure@...ts.grok.org.uk
Subject: has any ever tested a https portal?

Hi mismail, list,
mismail wrote


>the pin is one time unique! has anyone ever come across a setup like this?

Check out PINSafe by Swivel Secure (2 factor - unique PIN sent by email or
sms)
I found it during some app testing
It looked very good apart from the way it was implemented:Badly, it allowed
DoS any logged in user, by logging them off. The product was not to blame
IMHO - only how it was integrated to the web site
Best Regards
RARB

Content of type "text/html" skipped

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ