Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: Browser refresh sends username/password after log out -- URGENT

From: <najeeb.hatami(at)gsa.gov>
Date: Tue Aug 05 2003 - 07:41:39 EDT

Here is the answer to your question:

>From you browser:

click on Tools-> Internet Options-> click on Content tab -> then choose AutoComplete and un-check
User names and passwords on forms. This should solve the problem.

                                                                                                                   
                                                                                                                   
                    "K Kohli"            To:     webappsec@securityfocus.com                                       
                                      Subject:     Browser refresh sends username/password after log out --     
                                          URGENT                                                                   
                    08/05/2003                                                                                     
                    12:55 AM                                                                                       
                                                                                                                   
                                                                                                                   

I am into remote application testing for a critical banking application. The following points will make the question clear
1)We login and browse the banking site, do transactions etc and then logout from there. 2)We get a page saying you have been successfully logged out
3) Now we do a Back and refresh on the browser window and we get a pop up "The page cannot be refreshed without resending the information. Press retry to sending it again ...." .
4) From here we say "Retry" and watch the data going in a Web Proxy.
5) We are able to see the Username and password again being sent to the server. When we compare this request with the one sent from the first login page( Where we give the username/password), both are exactly the same. I feel thaat the same request is being resend. This is a great security risk as the credentials are being passed again.
6) Can anyone explain this behaviour and how to avoid the resubmission of the credentials. 7) How many requests does the browser window store in its temporary cache.



" DON'T WORRY BE HAPPY,
    EVERY NIGHT YOU HAVE SOME TROUBLE,
    IF YOU WORRY YOU MAKE IT DOUBLE,
    SO DON'T WORRY BE HAPPY NOW...."

Do you Yahoo!?
Yahoo! SiteBuilder - Free, easy-to-use web site design software http://sitebuilder.yahoo.com Received on Tue Aug 5 08:59:17 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:54 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library