[Full-Disclosure] Re: IRCXpro 1.0 - Clear local and default remote admin passwords]

From: northern snowfall (dbailey27_at_ameritech.net)
Date: 06/03/03

  • Next message: Darren Reed: "Re: [Full-Disclosure] Re: IRCXpro 1.0 - Clear local and default remote admin passwords"
    To: full-disclosure@lists.netsys.com
    Date: Tue, 03 Jun 2003 12:13:21 -0500
    

    >Then in this case this would be an operating system vulnerability.
    >
    >Overuse in the use of encrypted passwords can be counter productive to
    >functionality.
    >There are good reasons to keep passwords clear text passwords to better
    >interface with other software.
    >For example Merak Mail server software
    >(http://www.icewarp.com/Products/Merak_Email_Server_Software/)
    >When using this mail server, it can store the accounts on an SQL Server.
    >The passwords are stored clear text. This enables other software to
    >interface with its data to create and sync its accounts/passwords with other
    >systems.
    >
    Wow.

    http://deadchildren.org/~north_

    >

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Darren Reed: "Re: [Full-Disclosure] Re: IRCXpro 1.0 - Clear local and default remote admin passwords"

    Relevant Pages

    • Re: Mail program is malfunctioning
      ... any problem it has talking to your mail server. ... The chance that it's forgotten folks passwords is rather ...
      (comp.sys.mac.apps)
    • Re: What is the likelihood of password sniffing ?
      ... - there are logs kept on the mail server as to which ip address accessed ... passwords & usr names MUST be sent ... > I would guess at ISPs first, or maybe someone's PC that has been ... > where I have to receive un-encrypted financial information, ...
      (alt.computer.security)
    • Re: The myths of SBS
      ... >just a SYMPTOM of the failure of IT to SIMPLIFY their computer experience. ... >over smaller installations than strong passwords which are most always ... can authenticate against the mail server with the stolen credentials. ...
      (microsoft.public.windows.server.sbs)
    • Re: The myths of SBS
      ... >>failure short of a gadget. ... >>just a SYMPTOM of the failure of IT to SIMPLIFY their computer experience. ... >>over smaller installations than strong passwords which are most always ... > can authenticate against the mail server with the stolen credentials. ...
      (microsoft.public.windows.server.sbs)
    • password file recovery question
      ... I've had to rebuild a mail server from scratch, ... passwords are scrambled for most users. ... I did notice that if I already have passwords set before I copy the ...
      (freebsd-stable)