Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 17 Sep 2001 21:45:38 -0700
From:      "Ted Mittelstaedt" <tedm@toybox.placo.com>
To:        "Trevin Chow" <tmchow@sfu.ca>
Cc:        <questions@freebsd.org>
Subject:   RE: Passwordless Pine?
Message-ID:  <004b01c13ffc$c3702660$1401a8c0@tedm.placo.com>
In-Reply-To: <20010917213105.R13900-100000@benny.geektank.org>

next in thread | previous in thread | raw e-mail | index | archive | help
Yipe!!!!  Trevin, you better shut down that server pronto, you
may have just cooked your goose posting that here!!!!!

The IMAP port as of a year ago is full of security holes and
I understand several exploit scripts are out and about.

You want to fetch the current IMAP sources and look in the
"doc" directory for a file called SSLBUILD this will explain
things.  And get that old server replaced pronto or your going to
get cracked into.

Ted Mittelstaedt                                       tedm@toybox.placo.com
Author of:                           The FreeBSD Corporate Networker's Guide
Book website:                          http://www.freebsd-corp-net-guide.com


>-----Original Message-----
>From: Trevin Chow [mailto:tmchow@sfu.ca]
>Sent: Monday, September 17, 2001 9:32 PM
>To: Ted Mittelstaedt
>Cc: questions@freebsd.org
>Subject: RE: Passwordless Pine?
>
>
>I installed the imap-uw port and it's been functioning fine for hte past
>year, but I haven't yet tried to use SSHified connections with it until
>now.
>
>What docs exists to read up on setting up IMAPS?
>
>On Mon, 17 Sep 2001, Ted Mittelstaedt wrote:
>
>> Ahhhhhhh - I think at this point I'd better send you back to reread the
>> instructions for the SSHified IMAP server.
>>
>> What IMAP server are you even using here and how did you install it?!?
>>
>> Ted Mittelstaedt
>tedm@toybox.placo.com
>> Author of:                           The FreeBSD Corporate
>Networker's Guide
>> Book website:
>http://www.freebsd-corp-net-guide.com
>>
>>
>> >-----Original Message-----
>> >From: Trevin Chow [mailto:tmchow@sfu.ca]
>> >Sent: Monday, September 17, 2001 10:12 AM
>> >To: Ted Mittelstaedt
>> >Cc: questions@freebsd.org
>> >Subject: RE: Passwordless Pine?
>> >
>> >
>> >
>> >
>> >On Sun, 16 Sep 2001, Ted Mittelstaedt wrote:
>> >>
>> >> imaps only responds to port 993 of course, so if the Pine client
>> >was switching
>> >> to the regular IMAP server at port 143 behind my back then it would have
>> >> failed.  Ugly and crude, but effective.
>> >
>> >Oh wait.  Does this mean that I need to open port 993 in my firewall as
>> >well then?
>> >
>> >
>>
>>
>
>


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-questions" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?004b01c13ffc$c3702660$1401a8c0>