POP3 account passwords

SHSaeed

Well-Known Member
May 9, 2002
243
0
316
Hi,

We've noticed that the POP3 account passwords are compared to the begining of the entered password. For example, if your POP3 account password is &12345& and you type &1234567890& it will still let you login. You can login as long as your password is in the begining of the entered password.
 

rpmws

Well-Known Member
Aug 14, 2001
1,787
10
318
back woods of NC, USA
I found this out months ago ..but concluded that it really didn't matter.
 

SHSaeed

Well-Known Member
May 9, 2002
243
0
316
It might not be the most serious security bug, but it is still a bug that should be fixed. I'll submit it to bugzilla tomorrow if it's not already there by then.
 

Brad

Well-Known Member
Aug 16, 2001
229
0
316
Its like that because of the password length limit, it's always been like that. It lets you enter in longer passwords then allowed without an error, works for some people. Not really a security problem in my opinion.
 

SHSaeed

Well-Known Member
May 9, 2002
243
0
316
I don't get it, if your password is &qwerty&, why would you want to login with &qwerty123& ? That is the wrong password and the fact that you can still login with the wrong password is a security hole in my opinion.
 

SoftmegUK

Well-Known Member
Feb 13, 2002
368
0
316
UK
Well theres also of the bug of say you have the password &jilly1234& you can login with &jilly12&, &jilly123& or &jilly1234&. I think this is a bigger bug as it would then be easier to get in.
Eddy