security testing for "rembember password":
After excecuting the login screen i click the browser(Firefox and chorome) default button " remember password". Now the password will be stored in " saved password " area in the browser. but it does not encrypted, it shows the password i entered. It is correct or not.
that is the browser's functionality, not the website. Usually websites that have a remember me checkbox in login will just set a longer expiration on the session token that's stored in a cookie.
The browser does have to store in clear text, or encrypted with a fixed password (but this you'll have to retype each time if they do that).