Re: Checking on VPOPMail 1.00
Tomas Kuliavas <[email protected]>
| Newsgroups | gmane.mail.squirrelmail.devel |
|---|---|
| Message-ID | <[email protected]> |
Ignacio Agulló wrote:
>
>
> Today I felt that it was due for me to make a thorough check on
> the issue of VPOPMail and the passwords, so I spent my first hour at
> work doing it. (Unexpectedly for me at the moment, on the end this
> meant finishing work one hour later today). This is what I found.
>
> For a start, VPOPMail 1.00 accepts passwords from 1 to 15
> characters. Symbols count the same as the rest of the characters, so
> no re-encoding is apparent initially. Clicking on the "change
> password" button delivers a new webpage, with the phrase "Your
> settings have been saved" on top.
>
> If the password measures more than 15 characters, you still get
> the same webpage with "Your settings have been saved"... but on top of
> it, you get the following lines:
>
> ----- Start quote -----
> Error: password too long
> Warning: Cannot modify header information - headers already sent by
> (output started at
> /var/www/html/webmail/plugins/vpopmail/vpopmail.php:38) in
> /var/www/html/webmail/plugins/vpopmail/vpopmail.php on line 41
> ----- End quote -----
>
> Seems to be an uncaught exception there.
>
> After this, I decided to check on all the non-letters,
> non-digits characters from the ASCII code, which are:
>
> !\"#$%&\'()+,/:;<=>?@[\]^`{|}~
>
> And I actually found some problem, but not with the percent
> sign... it happens with the space. It happens this way: SquirrelMail
> seems to work all right with any password, but Thunderbird (and
> supposedly all POP clients) cannot receive messages if the password
> set with VPOPMail starts with spaces.
>
> - If the password is composed only by a space or a series of spaces,
> Thunderbird reports "syntax error".
> - If the password starts with a space or a series of spaces and after
> it/them has another caracters, Thunderbird reports "authorization
> failed".
>
> About the percent sign, it showed no problem today. I came
> across this problem about three months ago, and at the time I
> concluded that the percent sign was the cause. I was pretty sure of
> it, however todays results suggest it was caused by a space and not a
> percent sign. I'll keep an eye on this so if this problem happens
> again I will get sure of the reason of it.
>
> As for the URL-encode theory I advanced a couple of days ago,
> now it seems clear that I was wrong about it. I still don't know the
> cause, but seems clear to me that it has nothing to do with
> URL-encoding.
>
Both pop3 (rfc1939) and imap login (rfc3501) allow spaces in passwords.
Possible problem is unclear pop3 specification.
"Since the PASS command has exactly one argument, a POP3 server may treat
spaces in the argument as part of the password, instead of as argument
separators."
"may" is not same thing as "must"
Maybe pop3 service does not handle space correctly. Which pop3 server are
you using? qmail, courier or dovecot?
--
Tomas
--
View this message in context: http://old.nabble.com/Checking-on-VPOPMail-1.00-tp26973480p26977569.html
Sent from the squirrelmail-devel mailing list archive at Nabble.com.
------------------------------------------------------------------------------
This SF.Net email is sponsored by the Verizon Developer Community
Take advantage of Verizon's best-in-class app development support
A streamlined, 14 day to market process makes app distribution fast and easy
Join now and get one step closer to millions of Verizon customers
http://p.sf.net/sfu/verizon-dev2dev
-----
squirrelmail-devel mailing list
Posting guidelines: http://squirrelmail.org/postingguidelines
List address: [email protected]
List archives: http://news.gmane.org/gmane.mail.squirrelmail.devel
List info (subscribe/unsubscribe/change options): https://lists.sourceforge.net/lists/listinfo/squirrelmail-devel