Like Eric said ... this is only an issue if your mailserver has already been compromised and that's a much bigger problem. As far as the passwords go unless you're implementing encryption pop is sent in clear text and all someone needs is access to the network your mail server is on. After that it's a simple matter of a packet sniffer to harvest passwords.

Larry Craddock

----- Original Message ----- From: "Dmitri Elgin" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Tuesday, August 17, 2004 10:27 AM
Subject: RE: [IMail Forum] [Fwd: IpSwitch IMail Server <= ver 8.1 User Password Decryption]



I just have check my passwords,
It works

Sure bad thing

Regards,
Dmitri Elgin,
http://imailzip.com


-----Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Markus Gufler Sent: Tuesday, August 17, 2004 8:18 PM To: [EMAIL PROTECTED] Subject: RE: [IMail Forum] [Fwd: IpSwitch IMail Server <= ver 8.1 User Password Decryption]



This assumes that the intruder has access to the IMail
machine's registry...IMHO if this is so I would think you
have bigger problems than just grabbing passwords..

Eric S

Is it true that extractusers.exe will not work anymore above Imail v7.xx ? If not, with this code it should be easy to write a new extractusers.exe that will work exactly like the old version.

Markus



To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/



To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to