Dan,

I agree that the stolen-URL security hole is real and serious.
Session-control in the stateless http world is quite a trick, and
Ipswitch's method has been to use only URL variables to maintain
sessions.

There are only 2 methods by which a web application can maintain session
(recognize an authenticated user): by passing variables in the URL, or
by storing the session id numbers in a cookie in the user's browser.

I think it's a reasonable request of users to enable cookies in order to
use the WebMail templates. Likewise, I think it's a reasonable request
of Ipswitch to implement cookie-based session control (as an option)
into their next version of the WebMessaging module, which would
effectively eliminate this security hole.


Ron Allen Hornbaker       ����
Humankind Systems, Inc.    ~
mailto:[EMAIL PROTECTED]

~~HKSI WebMail Templates for IMail v6~~
Global Stylesheet Colors  ~  Fast Loads
ActiveX SpellCheck  ~  MacIE compatible
Try our demo...... http://mail.hksi.net




Please visit http://www.ipswitch.com/support/mailing-lists.html 
to be removed from this list.

Reply via email to