[1260] in WWW Security List Archive

home help back first fref pref prev next nref lref last post

Re: SECURITY ALERT: Password protection bug in Netscape 2.0b3

daemon@ATHENA.MIT.EDU (smb@research.att.com)
Mon Dec 18 17:35:55 1995

From: smb@research.att.com
To: DaVe McComb <dave.mccomb@gs.com>
cc: "Lincoln D. Stein" <lstein@genome.wi.mit.edu>,
        www-security@ns2.rutgers.edu, jcarroll@redman.canada.dg.com,
        tara@linkage.cpmc.columbia.edu
Date: Mon, 18 Dec 95 15:32:09 EST
Errors-To: owner-www-security@ns2.rutgers.edu

	 
	 I think you're getting the disk cache confused with Netscape's 
	 authentication.  Your demonstration page will not work correctly if
	 you flush the disk cache before attempting it.

I don't have 2.0b3, so I can't try the demo, but you may be making a
distinction without a difference.  The disk cache is, after all, on
disk, and persists between sessions.

home help back first fref pref prev next nref lref last post