RE: POP3

From: Burleson, Lee (IA) (Lee.Burleson@ia.ngb.army.mil)
Date: 02/28/02


From: "Burleson, Lee (IA)" <Lee.Burleson@ia.ngb.army.mil>
To: "'shady@netway.at'" <shady@netway.at>, "'security-basics@securityfocus.com'" <security-basics@securityfocus.com>
Date: Wed, 27 Feb 2002 22:17:36 -0600

Take the following into consideration...

Given:
        * POP3 authentication is clear text
        * MS Exchange authenticates against NT/2000 user accounts

Therefore:
        * The POP3 username & password are the same credentials used to
access network resources.
        * Compromised POP3 credentials will also compromise the entire
domain.

Conclusion: POP3 is a bad idea, even in a LAN.

- Lee

-----Original Message-----
From: shady@netway.at [mailto:shady@netway.at]
Sent: Saturday, February 23, 2002 4:00 PM
To: security-basics@securityfocus.com
Subject: POP3

My users want me to to give them POP3 access via
the firewall. We have an Exchange Server runnig with
a Checkpoint Firewall. Are there any security issues
that I need to watch out



Relevant Pages

  • Re: OWA email OK
    ... the CEICW and which have to be set manually. ... > in and manually set the RRAS firewall setting ... > "Need Port Open Help!" ... >>> A quick way to test and make sure POP3 is working on the server is to ...
    (microsoft.public.windows.server.sbs)
  • Re: How to make POP3 visible on Public Internet
    ... If you're using the SBS standard NAT firewall, you ... insert one called POP3 for port 110 and TCP. ... I have SBS Installed and working OK. ... Can I set up another organization, with second domain name, and also ...
    (microsoft.public.windows.server.sbs)
  • Re: Downloading email can not be completed
    ... Thank you Lan. ... After enabling spam mail failering for POP3 on firewall, ... downloading with attachment will has problem. ...
    (microsoft.public.exchange.admin)
  • Re: how can a firewall box handle virus?
    ... "Some new firewall boxes advertised DPI and virus protection (e.g. ... Let's say I'm downloading a pop3 email. ... Calling an illegal alien an "undocumented worker" is like calling a ...
    (comp.security.firewalls)
  • Re: Problems with pop3 through firewall
    ... > 5.5 mailserver and a windows 2000 server acting as a mail relay and spam ... both sitting behind an ISA firewall. ... > my mail relay as SMTP, and my exchange server as POP3 it was all working ...
    (microsoft.public.exchange.misc)