Form authentication security question!




Hello,
When my users logs in to my site, an MD5 hashed value of the password is
sent to the server, and there the value is validated against a database.

What if someone catchs my hash value and also send it to my server. Will
that form manipulation succeed?


Many thansk in advance

JJ


.



Relevant Pages

  • Re: Some user lose desktop settings after reboot
    ... outlook settings is still there. ... >>> Windows cannot unload your classes registry file - it ... >>> I only see this an average of 2 times on each server ...
    (microsoft.public.windows.terminal_services)
  • Re: Some user lose desktop settings after reboot
    ... Is there anything in the EventLog on the server regarding profile ... MCSE, CCEA, Microsoft MVP - Terminal Server ... Users are set up with terminal server roaming profiles. ... If a users logs off and then ...
    (microsoft.public.windows.terminal_services)
  • Cannot View CD contents
    ... I have a Windows XP client machine connected to Windows 2003 server. ... most of the times the users logs in locally to the XP machines and access ... cd is inserted the system show as a CD instered, However cant view any files ...
    (microsoft.public.windows.server.sbs)
  • Re: samba and win2003 PDC autentication
    ... > I have a PDC server which is windows 2003 server when a users logs on the ... > samba server it should be asked the user name and password of the windows ...
    (alt.os.linux.suse)
  • Some user lose desktop settings after reboot
    ... We have 4 Windows 2003 Terminal Servers. ... NLB and we are using a session server. ... login on Monday after a weekend reboot and report that their icons are in ... If a users logs off and then logs into a ...
    (microsoft.public.windows.terminal_services)

Loading