Uploaded image for project: 'James Server'
  1. James Server
  2. JAMES-44

User passwords are displayed in the log

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Resolution: Fixed
    • 2.0a3
    • None
    • POP3Server
    • None
    • Operating System: Other
      Platform: Other
    • 11234

    Description

      Contrary to standard security practices, the POP3Handler displays the user
      password in the log. This allows the administrator or anyone with read-only
      access to the server logs to gain access to users' mailboxes. Very bad. Very
      easy fix.

      Attachments

        Activity

          People

            Unassigned Unassigned
            farsight@alum.mit.edu Peter M. Goldstein
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: