[imp] Security of IMP

Chris Crowley ccrowley@tulane.edu
Wed, 7 Mar 2001 09:47:53 -0600


>
> > how can i test if my imp is secure?
>
> Wow, that's a big question.  :-)
>
> Start with making sure you have the latest version of Horde/IMP (1.2.4 and
> 2.2.4).  Follow the suggestions in imp/docs/SECURITY.  Make sure local
> users can't read your config/*.php3 files, and that the web server won't
> serve them.
>
> Try to break things, and tell us if you find anything.  :-)

Saint and Nessus will check your system for lots of potential
vulnerabilities. These are not directly related to imp, but can be run
against the box you are running imp on.

Chris