Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Web Authentication |
|---|---|
| Date: | Fri, 28 Jul 2006 08:39:09 +0200 |
Never use basic authentication for confidential data.What exactly you want to achieve by doing "better web authentication"? In you case, what are those weaknesses with htpasswd scheme?
I am asking because it is almost impossible to answer your question without additional info.
----- Original Message ----- From: "pimp mastermind" <gbchustla@gmail.com>
To: <security-basics@securityfocus.com>
Sent: Thursday, July 20, 2006 7:36 AM
Subject: Web Authentication
I have Slackware 10.1 runing. I am using it as a router and fileserver. I use Apache 1.3 for web access. I have some web directories which i want to secure more strongly than with htpasswd but i dont know any other ways of authentication.
Also a lot of my scripts in those directories are wirted in PHP Perl and CGI scripting. I need to find a better way of authentication? Does any one knows any better way of authentication?
There are many ways to achieve this, you can look for digest authentication, or you can make your own authentication script with SSL.
Thanks Emilio C.
--------------------------------------------------------------------------- This list is sponsored by: Norwich University
http://www.msia.norwich.edu/secfocus ---------------------------------------------------------------------------
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: How to stop Admins from sniffing ?, Dereck Martin |
|---|---|
| Next by Date: | Re: Deny client from obtaining IP address, Nathan Sportsman |
| Previous by Thread: | Re: Web Authentication, Florian Streck |
| Next by Thread: | RE: Web Authentication, Kamran Iqbal |
| Indexes: | [Date] [Thread] [Top] [All Lists] |