Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: Article - A solution to phishing |
|---|---|
| Date: | Fri, 26 Nov 2004 10:33:30 +0200 |
Hi Michael. I read the article, and was quite interesting. Scenario: Email is used as Login. The biggest problem to me would be that if the mail is intercepted, by a 3rd party with in the 15 minutes they have all the details to log in. Scenario: A PIN number is used as Login This would be a lot better. Since the 3rd party can see a password, when intercepting the email, but has no idea for which PIN number it can be used. Therefore the information sent to the users email is still save even in the short period. (Unless maybe the 3rd party is sniffing the HTTP and SMTP traffic). Our Rule of thumb is: One should never send all the details in an email that a person can use to log in. Regards Anton -----Original Message----- From: Michael Silk [mailto:michaels@phg.com.au] Sent: 23 November 2004 05:41 To: webappsec@securityfocus.com Subject: Article - A solution to phishing Hi, Just a quick little article about a login system that, should (i think :)), prevent phishing attempts on your site. http://michaelsilk.blogspot.com/2004/11/article-solution-to-phishing.htm l Have a look at it and let me know what you think ... and apologies to anyone if an idea like this is already out there :) -- Michael Confidentiality Warning ======================= The contents of this e-mail and any accompanying documentation are confidential and any use thereof, in what ever form, by anyone other than the addressee is strictly prohibited.
| Previous by Date: | IIS session & application variables, Bénoni MARTIN |
|---|---|
| Next by Date: | Re: Article - A solution to phishing, Saqib . N . Ali |
| Previous by Thread: | Re: Article - A solution to phishing, Paul Johnston |
| Next by Thread: | Re: Article - A solution to phishing, Michael Silk |
| Indexes: | [Date] [Thread] [Top] [All Lists] |