Neomail security

<[email protected]> Mon, 29 Nov 2004 17:18:23 +0100
Newsgroups gmane.mail.neomail.general,gmane.spam.detected
Message-ID <00ee01c4d62f$0fe4b3f0$c5b12250@NODOCASA>
This is a multi-part message in MIME format.

------=_NextPart_000_00EB_01C4D637.6E826080
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

In neomail th logout is not a real logout.
Try to login in neomail, and then make logout. You are sent to the login =
screen, but if you puch back button on explorer you'll get the message =
of page expired, then you update the page and you are inside neomail =
again, but you have not write yout login pass again!!!.
So, if anybody logout from neomail and leave the computer on (with the =
explorer open), another person could enter in his neomail account using =
the pages stored in history of browser.=20

I think neomail would have to accept the login from a refreshed expired =
page. The only way I've found is add a "time mark" in the login form and =
compare this time mark with a time mark calculated in the moment of =
login, if the difference is a few seconds the login is processed, but if =
the difference is too high the login is not processed. But there is a =
problem, if the user delays too time writing his login data the login is =
rejected too.

Regards
------=_NextPart_000_00EB_01C4D637.6E826080
Content-Type: text/html;
	charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=3DContent-Type content=3D"text/html; =
charset=3Diso-8859-1">
<META content=3D"MSHTML 6.00.2800.1476" name=3DGENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY bgColor=3D#ffffff>
<DIV><FONT face=3DArial size=3D2>
<DIV><FONT face=3DArial size=3D2>In neomail th logout is not a real=20
logout.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>Try to login in neomail, and then make =
logout. You=20
are sent to the login screen, but if you puch back button on explorer =
you'll get=20
the message of page expired, then you update the page and you are inside =
neomail=20
again, but you have not write yout login pass again!!!.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>So, if anybody logout from neomail and =
leave the=20
computer on (with the explorer open), another person could enter in his =
neomail=20
account using the pages stored in history of browser. </FONT></DIV>
<DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial size=3D2>I think neomail would have to accept =
the login from=20
a refreshed expired page. The only way I've found is add a "time mark" =
in the=20
login form and compare this time mark with a time mark calculated in the =
moment=20
of login, if the difference is a few seconds the login is processed, but =
if the=20
difference is too high the login is not processed. But there is a =
problem, if=20
the user delays too time writing his login data the login is rejected=20
too.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial =
size=3D2>Regards</FONT></DIV></FONT></DIV></BODY></HTML>

------=_NextPart_000_00EB_01C4D637.6E826080--




-------------------------------------------------------
SF email is sponsored by - The IT Product Guide
Read honest & candid reviews on hundreds of IT Products from real users.
Discover which products truly live up to the hype. Start reading now. 
http://productguide.itmanagersjournal.com/