LinuxQuestions.org
Review your favorite Linux distribution.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-23-2007, 08:11 AM   #1
sunlinux
Member
 
Registered: Feb 2006
Distribution: RHCL 5
Posts: 239

Rep: Reputation: 30
is squid ncsa_authentication is sniffable


Is squid ncsa_authentication is sniff able I mean it is possible to sniff user credentials from lan using any tool.
 
Old 08-24-2007, 01:08 AM   #2
gilead
Senior Member
 
Registered: Dec 2005
Location: Brisbane, Australia
Distribution: Slackware64 14.0
Posts: 4,141

Rep: Reputation: 168Reputation: 168
I'm assuming you mean basic type authentication - if so, yes it is. If you use Wireshark to sniff the traffic from the box you are running your browser from, you'll see a header called Proxy-Authorization followed by a base 64 encoded string. If you take that encoded string and decode it you'll be able to see your username and password in clear text. At least, it worked for me when I did it just now.

If you're trying to sniff someone else's password that's a different scenario and my advice is: don't.
 
Old 08-24-2007, 03:52 AM   #3
sunlinux
Member
 
Registered: Feb 2006
Distribution: RHCL 5
Posts: 239

Original Poster
Rep: Reputation: 30
Ok.. then how do I make it difficult to decrypet like 128 bit ?
 
Old 08-24-2007, 03:02 PM   #4
gilead
Senior Member
 
Registered: Dec 2005
Location: Brisbane, Australia
Distribution: Slackware64 14.0
Posts: 4,141

Rep: Reputation: 168Reputation: 168
I suggest having a look through the Squid authentication FAQ at http://wiki.squid-cache.org/SquidFaq...Authentication and see if anything there does what you need.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
SQUID for blocking yahoo and msn [inc squid.conf] chrisfirestar Linux - Security 10 03-03-2008 09:33 AM
Squid: special configuration for remote Squid server hamish Linux - Software 0 12-06-2005 04:58 PM
squid message customization, hiding squid versioin rajnishmishra Linux - Networking 0 11-27-2004 04:55 AM
squid conf: squid failed when I type insert redirect_program /usr/bin/squidguard Niceman2005 Linux - Software 1 11-24-2004 03:29 PM
Squid load testing software / Squid optimisation? gundelgauk Linux - Networking 2 08-31-2004 08:36 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:22 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration