[turba] Security problem

Matthias Mahrholz Matthias.Mahrholz@URZ.Uni-Magdeburg.DE
Mon Nov 18 08:30:54 2002


Hi,

I have a first user - Max Mahrholz - account 'mahrholz' at
    email-server 'sunny.urz.uni-magdeburg.de'.

I have a second user - Fritz Mahrholz - account 'mahrholz' at
    email-server 'freenet.de'

When either user login with
    Username: mahrholz
    Password: xxx
    Server: sunny.urz.uni-magdeburg.de
resp.
    Username: mahrholz
    Password: xxx
    Server: imap.freenet.de

to access user Max Mahrholz  a n d  user Fritz Mahrholz
to the same addressbook resp. options!!!

What is the solution?

Thanks,

Matthias

------------

to look at: http://matti.urz.uni-magdeburg.de

------------

conf.php:

$conf['server']['server_list'] = false;
$conf['server']['change_server'] = true;

server.php:

$servers['imap'] = array(
    'name' => 'IMAP Server',
    'server' => 'sunny.urz.uni-magdeburg.de',
    'protocol' => 'imap',
    'port' => 143,
    'folders' => '',
    'namespace' => 'INBOX.',
    'maildomain' => 'urz.uni-magdeburg.de',
    'smtphost' => 'smtp.urz.uni-magdeburg.de',
    'realm' => 'urz.uni-magdeburg.de',
    'preferred' => ''
);

Horde Versions

    Horde: 2.1
    IMP: 3.1 (run IMP tests)
    Turba: 1.1

 PHP Version

    View phpinfo() screen
    PHP Version: 4.1.2
    PHP Major Version: 4.1
    PHP Minor Version: 2
    PHP Version Classification: release
    You are running a supported version of PHP.

 PHP Module Capabilities

    FTP Support: No
    Gettext Support: Yes
    IMAP Support: Yes
    LDAP Support: Yes
    MCAL Support: No
    Mcrypt Support: No
    MySQL Support: Yes
    PostgreSQL Support: No
    XML Support: Yes

 Miscellaneous PHP Settings

    short_open_tag enabled: Yes
    magic_quotes_runtime set to Off: Yes
    file_uploads enabled: Yes

 PHP Sessions

    Session counter: 1
    To unregister the session: click here

 PEAR

    PEAR - Yes
    Recent PEAR - Yes
    Mail::RFC822 - Yes
    Log - Yes
    DB - Yes



More information about the turba mailing list