We have developed a few web apps. some of the apps are using ssl. however some of it is not including username and password section which I think it defeats the purpose. the developer that is in charge is assuring us it is secure, he does not want to secure it as it would cost us a few thoursand dollars since sharepoint is serving more than one site and we then would have to break them off to different servers.
I think this is not right, however I am unable to prove it. are there any utilities that I can buy to sniff the login username and password and any traffic that is submitted over WAN link or even on the internet side so that I can display it is a security breach.
This would be real world test, the developer is saying as long as the LAN is secured then they cannot sniff us from outside.
Basically what I am looking for is this:
a utility that I can point to the webserver from outside, then ask him to connect from another machine on the internet to the webserver and login, the sniffer would then get the username and password in which case I can raise my case. If I am not understanding this right then please shed some light on it so I can close the case and move on with his design.