Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 6 of 6
  1. #1
    Member
    Join Date
    May 2002
    Posts
    249

    Default POP3 account passwords

    Hi,

    We've noticed that the POP3 account passwords are compared to the begining of the entered password. For example, if your POP3 account password is &12345& and you type &1234567890& it will still let you login. You can login as long as your password is in the begining of the entered password.

  2. #2
    Member rpmws's Avatar
    Join Date
    Aug 2001
    Location
    back woods of NC, USA
    Posts
    1,858

    Default

    I found this out months ago ..but concluded that it really didn't matter.
    Just keeping my "eye" on things....
    R. Paul Mathews
    RPMWS - diehard cPanel Nutcase

  3. #3
    Member
    Join Date
    May 2002
    Posts
    249

    Default

    It might not be the most serious security bug, but it is still a bug that should be fixed. I'll submit it to bugzilla tomorrow if it's not already there by then.

  4. #4
    Member Brad's Avatar
    Join Date
    Aug 2001
    Posts
    236

    Default

    Its like that because of the password length limit, it's always been like that. It lets you enter in longer passwords then allowed without an error, works for some people. Not really a security problem in my opinion.

  5. #5
    Member
    Join Date
    May 2002
    Posts
    249

    Default

    I don't get it, if your password is &qwerty&, why would you want to login with &qwerty123& ? That is the wrong password and the fact that you can still login with the wrong password is a security hole in my opinion.

  6. #6
    Member
    Join Date
    Feb 2002
    Location
    UK
    Posts
    461

    Default

    Well theres also of the bug of say you have the password &jilly1234& you can login with &jilly12&, &jilly123& or &jilly1234&. I think this is a bigger bug as it would then be easier to get in.
    Eddy
    Apache to die or not to die, that is the question...

Similar Threads & Tags
Similar threads

  1. Old account passwords STILL WORK!
    By dansgalaxy in forum cPanel and WHM Discussions
    Replies: 8
    Last Post: 07-09-2009, 05:25 AM
  2. Obtaining POP3 passwords (running cppop)
    By mtindor in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 01-17-2007, 12:07 AM
  3. 2 different passwords for an account?!
    By iago in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 04-23-2003, 09:13 AM
  4. how to get account passwords ?
    By Radio_Head in forum cPanel and WHM Discussions
    Replies: 7
    Last Post: 07-31-2002, 07:48 AM
  5. Account passwords
    By awsol in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 02-16-2002, 07:53 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube