Re: SMTP AUTH LOGIN question

From: bugtraq (reitenba@fh-brandenburg.de)
Date: 01/29/03

  • Next message: James Taylor: "RE: Need recommendations about IDS Systems"
    From: bugtraq <reitenba@fh-brandenburg.de>
    To: security-basics@securityfocus.com
    Date: Wed, 29 Jan 2003 23:14:45 +0100
    
    

    Am Dienstag, 28. Januar 2003 21:56 schrieb Frank Barton:
    > I have seen many places saying "Don't use PLAIN or LOGIN methods for SMTP
    > AUTH, unless they are encrypted" Now my question is this: I've looked at
    > the actual transfer of an SMTP session where the AUTH LOGIN was used, and
    > the password wasn't sent in plain-text. Is it trivial to decrypt the
    > username and password that is sent across the wire, or is there some other
    > vulnerability?
    i think it's just only base64 encoded.

    buzz



    Relevant Pages

    • Re: SBS 2003 Smart host
      ... only bad thing is that that i need to setup my other mail server ... Just try to google string "The remote SMTP service rejected AUTH negotiation". ... but hell with exchange 2003 sbs server is painfull. ...
      (microsoft.public.exchange.admin)
    • Re: 2 sites and auth smtp
      ... I have auth setup using my a Dedicated SMTP virtual off of one of my ... site are connected over a WAN and each server has his own routing group. ... The company, which had installed the Exchange servers, said configuring ...
      (microsoft.public.exchange.connectivity)
    • Re: Relayberechtigungen einrichten
      ... erfolgreich auth. ... smtp Dienst neu starten). ... Kurze Beschreibung wie man an diversen Clients SMTP AUTH verwenden ... Next by Date: ...
      (microsoft.public.de.exchange)
    • Re: SMTP Logging
      ... Hallo Sascha, ... Dein Provider macht sicher entweder SMTP Auth oder POP before SMTP. ... Bei SMTP Auth kriegst Du genau die Fehlermeldung, wenn Dein Exchange ...
      (microsoft.public.de.exchange)
    • Re: Postifx as SMTP AUTH client
      ... I've configured Postfix ... How could the AUTH command be disabled at ... If you have to setup SMTP ... problem lies elsewhere in your postfix config. ...
      (Fedora)