LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-14-2009, 01:45 PM   #1
abefroman
Senior Member
 
Registered: Feb 2004
Location: lost+found
Distribution: CentOS
Posts: 1,430

Rep: Reputation: 55
Password blocked by hidden field, but in plain text when I view source


On a government website, in the password field my password is blocked by hidden field, but I can see my pass in plain text when I view source.

Is this a security issue?

Is this bad security practice?

(The page is over SSL, does anyone know if IE or FireFox cache SSL pages?)

TIA

Last edited by abefroman; 09-14-2009 at 01:52 PM.
 
Old 09-14-2009, 10:02 PM   #2
anomie
Senior Member
 
Registered: Nov 2004
Location: Texas
Distribution: RHEL, Scientific Linux, Debian, Fedora
Posts: 3,935
Blog Entries: 5

Rep: Reputation: Disabled
The pretty stars you see are just a property of the input type=password field (as rendered by your web browser) in a form.

The password still needs to get to its destination (hopefully the web server you intend for it to get to) when you hit submit, which is why you see it in the html. Think of the stars as complimentary obfuscation -- especially nice if someone is looking over your shoulder.
 
Old 09-15-2009, 08:06 AM   #3
abefroman
Senior Member
 
Registered: Feb 2004
Location: lost+found
Distribution: CentOS
Posts: 1,430

Original Poster
Rep: Reputation: 55
Quote:
Originally Posted by anomie View Post
The pretty stars you see are just a property of the input type=password field (as rendered by your web browser) in a form.

The password still needs to get to its destination (hopefully the web server you intend for it to get to) when you hit submit, which is why you see it in the html. Think of the stars as complimentary obfuscation -- especially nice if someone is looking over your shoulder.
Should the password also be obfucated, or encrypted in the source code? IE. with symmetric encryption.
 
Old 09-15-2009, 11:15 AM   #4
anomie
Senior Member
 
Registered: Nov 2004
Location: Texas
Distribution: RHEL, Scientific Linux, Debian, Fedora
Posts: 3,935
Blog Entries: 5

Rep: Reputation: Disabled
It may be a little bit questionable that they're retrieving your password and then populating a form field with it -- that seems unnecessary unless there is a functional reason to do so. It also clearly indicates that they're storing your password instead of a hash.
 
Old 09-15-2009, 11:21 AM   #5
abefroman
Senior Member
 
Registered: Feb 2004
Location: lost+found
Distribution: CentOS
Posts: 1,430

Original Poster
Rep: Reputation: 55
Quote:
Originally Posted by anomie View Post
It may be a little bit questionable that they're retrieving your password and then populating a form field with it -- that seems unnecessary unless there is a functional reason to do so. It also clearly indicates that they're storing your password instead of a hash.
That's pretty insecure if you ask me. Especially for a government website that contains sensitive data.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How much can I edit in plain text? JosephS Linux - Software 4 04-29-2009 09:08 PM
plain old text editor autophil Linux - General 9 08-12-2007 08:46 PM
CMS for plain text rblampain Linux - Software 3 12-14-2005 10:40 PM
not a plain text file wazza4610 Linux - Newbie 1 11-22-2005 04:20 AM
passing anonymous hash in CGI hidden field wonderdog33 Programming 1 01-30-2004 11:19 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:19 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration