It was said:
Can we take the discussion off list now??? I'd rather not "hear" the
bickering any longer
Thanks
Anthony
Before the discussion disappears, I'd like to say that when I got the alert, I went
over to the server and double-checked that it was as difficult as possible to gain
console access to that sucker as possible while still permitting administrators
access. My understanding of the situation is the potential troublemaker needs console
access to get at the registry, unless remote registry administration is enabled on the
server. In the latter case, we still need to get around NT security to get into the
registry to read the IMail user passwords. So this exploit is of limited utility on a
properly-secured system, no?
'Course we're set up with the NT database, in which case our passwords DON'T reside in
the registry, anyhow. Likewise for anyone with an external database, no?
So this is a problem for those using the basic installation on a relatively unsecured
server, right?
If I am wrong in my relative lack of interest in this "problem", will someone please
slap me?
--Cal Frye, Western Reserve Academy, Hudson, OH
Please visit http://www.ipswitch.com/support/mailing-lists.html
to be removed from this list.