Hello!


Friday, January 05, 2001, 12:46:48 AM, Adam <[EMAIL PROTECTED]> wrote:

A>   I'm using The Bat! Version 1.48f
A>   Serial Number 4E83F57A
A>   under Windows NT 5.0 Build 2195 Service Pack 1
A>   and would like to report a bug

  
A>   The bug description:

A> I have cc'd this to the list, as it seems to me to be a security
A> risk as well as a bug.

A> I have an account which I just use for a mailing list, as the list
A> sets the reply to to the sender and the list address, I have set the
A> reply to in the accounts properties to the list address.

A> Today in error I started creating an e-mail in the mailing list
A> account, that should have gone from my general account, as it happened
A> this was a technical support query and contained a product licence
A> key. I noticed before sending I had chosen the wrong "active account",
A> and changed from my mailing list account to my general account.

A> The technical support people hit reply to reply to my message, and the
A> "reply to" had not changed when I selected the correct "active
A> account", and so their reply went to a mailing list.

A> In this instance this seems to be quite a major security flaw, as I
A> often start in the wrong account, and then use options/active account
A> to change it, the fact that the reply to doesn't change could be a
A> security risk, or for people using The Bat for say work/private
A> messages, potentially very embarrassing.

Couldn't confirm, may be I have missed something in your mail?

Personally I have 14 accounts (2 of them are phantom, but this doesn't
matter). About half a minute ago I started composing a test message and
then changed an Active account through the Options - Active Account
menu. The From address changed as well as Reply-To; the only thing that
remains untouched is my sig which is different from one account to
another.


-- 

Yours sincerely,

Andrey G. Sergeev (AKA Andris)     http://www.andris.msk.ru/

-- 
--------------------------------------------------------------
View the TBUDL archive at http://tbudl.thebat.dutaint.com
To send a message to the list moderation team double click here:
   <mailto:[EMAIL PROTECTED]>
To Unsubscribe from TBUDL, double click here and send the message:
   <mailto:[EMAIL PROTECTED]>
--------------------------------------------------------------

You are subscribed as : [email protected]


Reply via email to