Search This Blog

Tuesday, June 15, 2010

Html Forms Autocomplete = OFF - OWASP

HTML forms are a key component to exchanging information between a user and the server.
browser feature of remembering what you entered in previous text form fields with the same name. So, for example, if the field is named name and you had entered several variants of your name in other fields named name, then autocompletion provides those options in a dropdown. This image shows autocompletion being used in a form field:


Generally autocompletion is a useful browser feature, but occasionally it can be harmful. If the form field contains information such as a credit card number that should be left stored on the user's hard drive then you should turn autocompletion off. You can turn it off by setting AUTOCOMPLETE to OFF:


<input autocomplete="off" name="oPassword" type="password" > 
TIPS:-
1. Confidential Information must be OFF.

No comments:

Hit Counter


View My Stats