Solved

Adding Username and Password to URL for login purposes...

Posted on 2006-10-26
11
4,749 Views
Last Modified: 2008-03-04
Hello,

Is it possible to send a URL (link) to a user that includes their username and password to allow them to log into the Exchange OWA system without having to manually enter their credentials?

Something like: https://exchange.mycompany.com/exchange/?user=john&password=public

0
Comment
Question by:iain_stephen
  • 4
  • 4
  • 2
11 Comments
 
LVL 24

Accepted Solution

by:
flyguybob earned 350 total points
ID: 17814992
...my guess is that you have a politically powerful person (executive, salesperson, etc). asking this because entering a username and password is annoying them
Due to security, my understanding is nope.  This would also defeat the purpose of having security as the URL information goes over cleartext until the SSL session is established.
You can't do https://username:password@exchange.mycompany.com/exchange either, that I know of.
0
 
LVL 104

Expert Comment

by:Sembee
ID: 17815061
Wasn't the username:password functionality disabled in Internet Explorer a while ago?

Simon.
0
 
LVL 24

Expert Comment

by:flyguybob
ID: 17815235
...just trying to be careful with my wording as the member agreement for E-E is clear on hacks...It still works for certain URL types, such as FTP, but MS04-004 removed this "feature" from the http:// and https:// as it was determined to be a security risk.  To the best of my knowledge, there is no URL workaround available.

KB834489 is pretty clear on it (http://support.microsoft.com/kb/834489)
MS04-004 - http://www.microsoft.com/technet/security/bulletin/MS04-004.mspx
The associated KB for MS04-004 is KB832894, which has a link to the above.
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 104

Expert Comment

by:Sembee
ID: 17815257
I thought so.
It was being used in phishing attacks to hide the real URL.

Simon.
0
 

Author Comment

by:iain_stephen
ID: 17815988
Hi Guys - well you hit the nail right on the head, actually...  I have a few board members who simply cannot be bothered with remembering their passwords - and as such they insist that it is a problem with the system...

My plan was to use Indigo Rose Autoplay Studio to construct a specific application that would launch OWA in a self-contained browser window (I have done this before for other tasks - such as kiosks) but have the URL contain their login credentials...  This would be invisible once the executable was published as there is no address bar in the browser window of the application...

Is there any other way to have OWA authenticate a user using scripting?

Iain
0
 

Author Comment

by:iain_stephen
ID: 17816074
Ok - I found this - I get an ActiveX warning when I run it but it will work I think...

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" />
<title>AutoLogon</title>
</head>
<body onload="document.logonForm.submit();">
<FORM action="https://exchange.mycompany.com/exchweb/bin/auth/owaauth.dll" method="POST" name="logonForm">
     <INPUT type="hidden" name="destination" value="https://exchange.mycompany.com/exchange" />
     <INPUT type="hidden" id="username" name="username" value="john">
     <INPUT type="hidden" id="password" name="password" value="public">
</FORM>
</body>
</html>
0
 
LVL 24

Expert Comment

by:flyguybob
ID: 17820200
I would recommend against that, even if it is going to be a link on their desktop.  However, politics and convenience almost always trump security and common sense.
0
 

Author Comment

by:iain_stephen
ID: 17822087
I understand your concern - and appreciate your understanding.
0
 

Author Comment

by:iain_stephen
ID: 18027633
I am awarding the points because of the astute reply regarding the politics behind the question.
0
 
LVL 24

Expert Comment

by:flyguybob
ID: 18081255
I forgot to say Thanks.

Thanks for understanding and thanks for the points!
0

Featured Post

Best Practices: Disaster Recovery Testing

Besides backup, any IT division should have a disaster recovery plan. You will find a few tips below relating to the development of such a plan and to what issues one should pay special attention in the course of backup planning.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Following basic email etiquette rules will help you write a professional email and achieve a good, lasting impression with your contacts.
A list of top three free exchange EDB viewers that helps the user to extract a mailbox from an unmounted .edb file and get a clear preview of all emails & other items with just a single click on mailboxes.
In this video we show how to create a Contact in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Contact ta‚Ķ
To show how to generate a certificate request in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Servers >> Certificates‚Ķ

829 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question