AnsweredAssumed Answered

Qualys against web server using plain text

Question asked by Donald Tang on Sep 24, 2013

Hi guys,

 

My company is using Qualys VM. We've noticed Qualys uses QID 86763 and 86728 to find web servers using plain text.  We've found some web servers using plain text which haven't ever been found by Qualys.

Obviously they're using code "inputtype = password". So here comes the question, does Qualys have any signature against it? To which QID does it relate?

Thank you very much!

Outcomes