[8438] in bugtraq

home help back first fref pref prev next nref lref last post

Re: Communicator 4.5 stores EVERY mail-password in preferences.js

daemon@ATHENA.MIT.EDU (HD Moore)
Fri Nov 6 13:23:23 1998

Date: 	Wed, 4 Nov 1998 17:33:42 -0600
Reply-To: HD Moore <hdmoore@USA.NET>
From: HD Moore <hdmoore@USA.NET>
To: BUGTRAQ@NETSPACE.ORG

This is a multi-part message in MIME format.

------=_NextPart_000_0036_01BE0819.444AA5E0
Content-Type: text/plain;
        charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

One more thing I forgot to mention, the password stored in the registry =
is NOT the same as the one stored in prefs.js, but the encryption method =
seems the same.  I wonder if your proxy server logon, news logon, and =
other assorted passwords are stored in the same way...

------=_NextPart_000_0036_01BE0819.444AA5E0
Content-Type: text/html;
        charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD W3 HTML//EN">
<HTML>
<HEAD>

<META content=3Dtext/html;charset=3Diso-8859-1 =
http-equiv=3DContent-Type>
<META content=3D'"MSHTML 4.72.3510.1400"' name=3DGENERATOR>
</HEAD>
<BODY bgColor=3D#ffffff>
<DIV><FONT color=3D#000000 size=3D2>One more thing I forgot to mention, =
the password=20
stored in the registry is NOT the same as the one stored in prefs.js, =
but the=20
encryption method seems the same.&nbsp; I wonder if your proxy server =
logon,=20
news logon, and other assorted passwords are stored in the same=20
way...</FONT></DIV></BODY></HTML>

------=_NextPart_000_0036_01BE0819.444AA5E0--

home help back first fref pref prev next nref lref last post