Hi All + Ipswitch:

I think I've mentioned to Ipswitch regarding about this security hole.  The
problem is as follow:

1. If you send a message to one of the Imail user and ask him/her to visit
   your website.  For example in the message body:

   Win a BMW today, visit http://www.anydomain.com

2. Then the user clicks on the link and come to your site.  If you run a
program
   or a server-side script to see where that user comes from.  You can
capture
   an information like this, for example:


http://mail1.anydomain.com/Xb8489e93ccce999a989d65af9fa5/readmail.38327.cgi?
uid=eshop101u1&mbx=Main

3. Next, all you have to do is go to the above link and voila you're in
their mailbox (provided
   that the user is still in his/her email).  Anything after that, you will
get the point.


Note: I know that you can uncheck "Ignore Source IP..." box, but chances are
many Imail servers
will have this box checked to for AOL users.

Anyone wants to see the demo, I can arrange this.  We actually tested this
and we can hack into
anyone's mailbox (change their password, do many other things, etc...) and
took total control.

This is serious security hole, don't you all think?

Dan


_____________________________________________________

Build Your Biz, E-Commerce, WebSite and more online. 
Visit http://www.hotbiz.com

Please visit http://www.ipswitch.com/support/mailing-lists.html 
to be removed from this list.

Reply via email to