Re: POP3 risk over the internet

From: Alan J. Flavell (flavell@mail.cern.ch)
Date: 12/15/01


From: "Alan J. Flavell" <flavell@mail.cern.ch>
Date: Sat, 15 Dec 2001 19:14:13 +0100

On Dec 15, Giles Coochey inscribed on the eternal scroll:

> The risk with POP3 is that the username and password of each user's mailbox
[..]
> passed in clear text over the Internet.

This risk is not exclusive to POP3, although POP sends the credentials
whenever it checks for new mail, which can be rather frequently.

However, POP can be SSL-wrapped (as can some of the other protocols
which exchange clear-text credentials).

And/or there are safer ways of exchanging credentials (but if that's
your only security measure, then sure, the mail itself would still be
sniffable in plain text).

> Anyone able to run a packet sniffer
> on the network between connecting end-nodes and your exchange server would
> be able to glean the username and password of users.

Which is true of all protocols which exchange plain-text credentials.

Like all security issues, I'd say the hon Usenaut needs to audit their
requirements and the feasible solutions, and make a selection which is
appropriate to their situation. There is no magic bullet that
represents the ideal solution for everyone's requirements,
unfortunately.

SSL-wrapped IMAP has a number of attractions, for sure.



Relevant Pages

  • Re: Login Auditing
    ... I will check if any Windows and/or Exchange updates were been installed. ... I am leaning more towards someone trying to hack the server, ... There is diagnostic logging in ESM for pop3. ... I would need to get at least the username and source IP ...
    (microsoft.public.exchange.admin)
  • Re: Login Auditing
    ... Outlook Express is configured to use just the username. ... only problem is with POP3. ... I will check if any Windows and/or Exchange updates were been installed. ...
    (microsoft.public.exchange.admin)
  • Re: cannot connect to pop3 on exchange
    ... For POP3 to work the Exchange alias has to be identical to the username. ...
    (microsoft.public.windows.server.sbs)
  • Re: POP3 und IMAP4 virtuelle Server stehen auf offline
    ... als Username etwas wie username@providerserver und der Virenscanner macht dann die POP3 Verbindung zum Provider als "username" auf. ... und kann so beim Download schon Viren finden ehe Sie bei deinem Client ankommen. ... Auf localhost läuft der Exchange POP3 Dienst. ...
    (microsoft.public.de.exchange)
  • Re: configure POP3
    ... client mailboxes. ... Exchange 2003 doesn't activate the POP3 service by default. ... Services and set the POP3 to Automatic and then start the service. ... the server name, the credentials etc.) ...
    (microsoft.public.exchange.setup)