You should call IPSwitch Directly with this problem so their programmers can
fix this.

Deric Pantry
Clariti IP

----- Original Message -----
From: "Dan Nguyen" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Friday, February 25, 2000 8:35 PM
Subject: [IMail Forum] Big Ipswitch's Imail Security Hole.


> Hi All + Ipswitch:
>
> I think I've mentioned to Ipswitch regarding about this security hole.
The
> problem is as follow:
>
> 1. If you send a message to one of the Imail user and ask him/her to visit
>    your website.  For example in the message body:
>
>    Win a BMW today, visit http://www.anydomain.com
>
> 2. Then the user clicks on the link and come to your site.  If you run a
> program
>    or a server-side script to see where that user comes from.  You can
> capture
>    an information like this, for example:
>
>
>
http://mail1.anydomain.com/Xb8489e93ccce999a989d65af9fa5/readmail.38327.cgi?
> uid=eshop101u1&mbx=Main
>
> 3. Next, all you have to do is go to the above link and voila you're in
> their mailbox (provided
>    that the user is still in his/her email).  Anything after that, you
will
> get the point.
>
>
> Note: I know that you can uncheck "Ignore Source IP..." box, but chances
are
> many Imail servers
> will have this box checked to for AOL users.
>
> Anyone wants to see the demo, I can arrange this.  We actually tested this
> and we can hack into
> anyone's mailbox (change their password, do many other things, etc...) and
> took total control.
>
> This is serious security hole, don't you all think?
>
> Dan
>
>
> _____________________________________________________
>
> Build Your Biz, E-Commerce, WebSite and more online.
> Visit http://www.hotbiz.com
>
> Please visit http://www.ipswitch.com/support/mailing-lists.html
> to be removed from this list.
>

Please visit http://www.ipswitch.com/support/mailing-lists.html 
to be removed from this list.

Reply via email to