[2675] in bugtraq
Re: Attacks using pop
daemon@ATHENA.MIT.EDU (simes@tcp.co.uk)
Tue Jun 4 18:41:23 1996
Date: Tue, 4 Jun 1996 17:16:57 +0100
Reply-To: Bugtraq List <BUGTRAQ@netspace.org>
From: simes@tcp.co.uk
To: Multiple recipients of list BUGTRAQ <BUGTRAQ@netspace.org>
In-Reply-To: <Pine.SUN.3.90.960604171316.6463H-100000@papaioea.manawatu.gen.nz> from "Alan Brown" at Jun 4,
96 05:25:49 pm
Alan Brown said
>
>If the collecting client times out, the ~/user.pop is appended back onto
>~/user. If the client times out while the .user.pop file is being
>built, ~/user isn't zeroed but ~/.user.pop is still appended
Thist really depends on the POP3 server you are using. It should really
just read directly from the .pop file and ignore the actual mailbox.
Certainly, this is how the POP3 server we have works. I would say that
any POP3 server that appends the .pop file back onto the mail box itself
when it loses the connection to the POP3 client is broken.
--
Simon Burr | SysAdmin and Programmer, TCP Ltd
simes@tcp.net.uk/simes@bofh.org.uk | http://www.tcp.co.uk/staff/simes/
I *don't* speak for my company, my boss does that
cd /pub/lunch || dd if=/dev/zero of=/dev/mem