Can someone tell us what is going on with what the user below is mentioning in their email to us? We had one of the guys in our office do the same thing and just like our customer says in the email below the password in the web mail interface was sent in plain text. We will switch server software in a heart beat if this is not a fixable item. Has anyone else ran across this?? Gives a big security risk for our customers passwords. Rob Smarzik RJSOnline, LLC
cc: TO customer, we have reported this to an IMail list that is monitored by IPSwitch makers of IMail and hope to have a answer back shortly. ----- Original Message ----- From: "Robinson" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Friday, December 07, 2001 3:24 PM Subject: re. security on webmail > Hi, Rob; > Today we were using admin tools at New Horizons, and a capture of network. > We experimented, and captured my password from rjsonline.net webmail. > > Rob, this password is not encrypted, and is being sent across the network in plain text. > Perhaps you can jump on someone there regarding the security of our email and passwords. I am a bit shaken at how easily the password was obtained by using a regular protocol analyzer sniffing for my password over the internet. > Let me know when this will be resolved so that I can use rjsonline webmail in a secure manner. > Hotmail definitely was encrypted, as is yahoo. > Thanks, > Billie > Please visit http://www.ipswitch.com/support/mailing-lists.html to be removed from this list. An Archive of this list is available at: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
