+ Reply to Thread
Results 1 to 2 of 2

Thread: Is my webSite Secure?

  1. #1
    purple_banana_ftp87 is offline x10Hosting Member purple_banana_ftp87 is an unknown quantity at this point
    Join Date
    Jun 2011
    Posts
    2

    Is my webSite Secure?

    I made a login web page and I want to know if anyone can test for any security holes. The link to page is:

    http://www.purplebananaftp.pcriot.com/pass.html

    There is a secret token code I have set up too, So if you manage to break it please inform me with the token. And then tell me what programing launuge it is written in.
    Thanks ;)

  2. #2
    essellar's Avatar
    essellar is offline Community Advocate essellar has a spectacular aura about
    Join Date
    Feb 2010
    Location
    Toronto, Ontario, CA
    Posts
    1,153

    Re: Is my webSite Secure?

    No, it's not. And the reason it's not secure is that there is only one password for everybody. If that one password leaks, then the site is essentially wide open -- since every user shares the same password, you can't just change the password when the site is compromised, since that will lock everyone out. It doesn't matter what kind of code you are using to check the password or how "impossible" it is to get into the site without the password, the fact is that every single user of the site is a "secret keeper", so you only need one careless person to bring the whole thing down. (And since you aren't using https -- and can't on free shared hosting -- the password is transmitted "in the clear", anyone who uses your site over open wifi is a leak; openly available tools like FireSheep make getting the password easy.) Every user should have their own password. That way, if one password is compromised you can change just that password without bringing down the whole site.

    Don't get clever. Good security means using something that the "enemy" can know absolutely everything about and still not get in quickly enough to make it worth their while. See this thread in the "Scripts" forum; the basic requirements are pretty thoroughly covered there.
    “Beware of bugs in the above code; I have only proved it correct, not tried it.” --Donald Knuth
    "It was as if its architects were given a perfectly good hammer and gleefully replied, 'neat! With this hammer, we can build a tool that can pound in nails.'" -- Alex Papadimoulis (on TheDailyWTF.com)

+ Reply to Thread

Similar Threads

  1. Secure a vps?
    By high6 in forum VPS Talk
    Replies: 4
    Last Post: 06-13-2010, 08:23 AM
  2. Replies: 4
    Last Post: 05-14-2010, 09:33 AM
  3. SMF - Is it secure?
    By Fearghal in forum Scripts & 3rd Party Apps
    Replies: 4
    Last Post: 11-25-2009, 06:18 PM
  4. How can I secure my website?
    By kentzy99 in forum Tutorials
    Replies: 7
    Last Post: 06-30-2009, 09:35 AM
  5. Just how secure is MD5?
    By KentonBomb in forum Scripts & 3rd Party Apps
    Replies: 5
    Last Post: 02-22-2008, 02:32 AM

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
x10hosting free hosting for the masses
dedicated servers