After having done a number of secure sites, by far the easiest method to thwart packet sniffers is to use https. It is a simple configuration change to enable SQL-LEDGER to operate within it once your https is installed and operating.


Antonio Gallardo Rivera wrote:
Hi Dieter:

I saw a little security problem in SQL Ledger:

Problem:
Some one can get your account name and password.

How:
With a TCP/IP packet sniffer someone can check the responses from the Web 
Server inside your LAN or Internet. When the Web Client is receiving the menu 
sidebar, there are many time the username and password in plain text!

Resolution:
First: I am not a security expert to tell exactly how to resolve this problem. 
May be using encrypted password or some kind of session cokies can help us. I 
saw some encrypt libraries in Perl.

Regards,

Antonio Gallardo




El S�bado, 10 de Agosto de 2002 21:08, William Hamilton escribi�:
  
I am after some comments form people using SL as a point of sale
application.  I have a client who has asked me to develop an application
to track sales, inventory and commissions for sales people in the store.

SL sprung to mind as a good option.. any comments or experiances?

tia
    


-------------------------------------------------------
This sf.net email is sponsored by:ThinkGeek
Welcome to geek heaven.
http://thinkgeek.com/sf
-------------------------------------------------------
(un)subscribe: http://lists.sourceforge.net/lists/listinfo/sql-ledger-users
Archive: http://www.mail-archive.com/[email protected]/

  

Reply via email to