[imp] error in logon

Chris Swenson cswenson at students.curry.edu
Mon Nov 10 10:44:06 PST 2003


This is very strange, I hope I can make clear what happened.  It concerns me 
deeply due to the security implications.

3 off campus students in the same class.
Student Cathy claims she started her computer from a power off condition, 
connected to her email without passing a username or password.

Cathy says she sent an email to Anne but then realized she sent it as Jim. ( 
don't know how she realized this, kids)

Researching the horde.log, and the web server logs and e-mail logs confirm 
that an email was sent from Cathy's IP address to Anne but that the "sent 
from" reflects Jim's email address.

There is an email in Jim's out box to Anne, There is an email in Anne's inbox 
from Jim, but Cathys IP address is at the header.

Jim and Cathy were logged into the network at the same time. 
Could imp have passed the wrong cookie with the id to a user? 

context
Red Hat 7.1
IMP 3.0-1
HORDE 2.0-1

(I will be upgrading the whole kit and caboodle this winter break)





-------------------------------------------------
Visit us at http://www.curry.edu/welcome


More information about the imp mailing list