Guy wrote:

> Quoting from http://support.ipswitch.com/kb/IM-20020703-DM02.htm:

> "Any Type of Password Protected List w/Posters List

> IMail  v7.10:  You  must use the correct password AND you must be on
> the  posters  list

> IMail v7.11: You must use the correct password OR you must be on the
> posters list"

> So, if someone usurps "a permissioned poster's Reply-To: and us[e] it as
> their From:", he or she does not need to use the correct password in v7.11,
> according to the above KB article.

Right  on,  Guy.  This  is  an  INSANE change! This removes the *only*
semblance of real security that Imail lists can have! I cannot imagine
why   this  functionality  was  adjusted  to  make  every  IMail  list
vulnerable  to  header  spoofing. Now *this* is a new security/privacy
hole,  worse  than  the  badly  managed  somewhat-fix that's the other
hot-topic list issue.

Ipswitch, we need to hear from ya (copied to [EMAIL PROTECTED]).

-Sandy


Please visit http://www.ipswitch.com/support/mailing-lists.html 
to be removed from this list.

An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/

Please visit the Knowledge Base for answers to frequently asked
questions:  http://www.ipswitch.com/support/IMail/

Reply via email to