RE: password protected webpages

by Chuck Evans <Chucke(at)captura.com>

 Date:  Wed, 5 Apr 2000 11:02:49 -0700
 To:  "'Peter Benoit'" <pbenoit(at)triton-network.com>,
"'rudy limeback'" <r937(at)interlog.com>,
Brockfamily(at)xtra.co.nz,
hwg-techniques(at)hwg.org
  todo: View Thread, Original
Basically, the password your user provides gets ".htm" appended to it and it
forms a new URL for the user to go to. You're right that, if the page is
named something like lkoish34er.htm that there is little chance someone will
guess it outright.

However, that scheme will work only as long as you have just one user or
have multiple users who don't compromise your "password". Either that or
you'll have to generate a new destination page every day and email out the
new "password" daily to your users. Or, even more unlikely, you'll need to
duplicate the page for each user who has a different "password".

I guess technically you have succeeded, but not practically.

---------------------------------------------------------
Chuck Evans
Web Marketing Manager
Captura Software, Inc.
(425) 424-1155
chucke(at)captura.com
www.captura.com

-----Original Message-----
From: Peter Benoit [mailto:pbenoit(at)triton-network.com]


LoL

Try to crack my JS protected password page. ;)

http://www.iguy.net/JS/password.htm

<snip>

HWG hwg-techniques mailing list archives, maintained by Webmasters @ IWA

This page is part of a preserved archive of archives.hwg.org. The site is no longer active and its content is not maintained. For enquiries about this archive, write to archive(at)iwanet.org.