[imp] Fwd: HORDE/IMP: Password not encapsulated properly

Chuck Hagenbuch chuck at horde.org
Tue Oct 14 19:33:14 PDT 2003


He doesn't say what version; this is fixed in all of the current ones, though,
so it can't be that recent.

----- Forwarded message from mbradfor at isrc.qut.edu.au -----
    Date: Wed, 15 Oct 2003 11:30:08 +1000
    From: Matt Bradford <mbradfor at isrc.qut.edu.au>
Reply-To: Matt Bradford <mbradfor at isrc.qut.edu.au>
 Subject: HORDE/IMP: Password not encapsulated properly
      To: chuck at horde.org

Hi Chuck,

I did not want to send this straight to a person - i tried your bug report thing
but it would not send me a password - so i could not login to submit a report.

I have a problem with the IMP system. my password contains a '\' at the end of
it - when my password has this in it and i try to login to the IMP system it
does not authenticate. However if i change my password to what it was without
the '\' then it works. Could you please fix this? I know there's plenty of PHP
functions to encapsulate all these characters safely.

We've only just set the IMP up and is currently in development, however we will
not be able to deploy it as a webmail solution if we can't guarantee everyones'
password will work - we may have to find another solution. Please let me know
what you guys can do about this password problem.

Cheers,
Matt


--------------------------[oo00oo]--------------------------
Matt Bradford

Research Assistant
Information Security Research Centre
Queensland University of Technology
Brisbane, Australia
(Cricos Institution Code: No. 00213J)

Email: m.bradford at isrc.qut.edu.au
Phone: +61 (07) 3864 9512 (QUT Extension 9512)

--------------------------[oo00oo]--------------------------




----------------------------------------------------------------
This message was sent using IMP, the Internet Messaging Program.



----- End forwarded message -----


-chuck

--
Charles Hagenbuch, <chuck at horde.org>
Born right the first time.


More information about the imp mailing list