Security Basics mailing list archives
Sniffing emails - how?
From: Derek Fountain <dflists () iinet net au>
Date: Sat, 13 Nov 2004 10:50:12 +0800
Reading the archives of this and other lists, I occasionally come across quotes like this (from the WebApp list in this case): "2/ That sending a user's password in clear text over email systems is a secure method; inappropriate for most sites. For example, an attacker could provoke the password recovery procedure for his colleague and sniff the email containing the password with relative ease." Am I correct in thinking that this is only a real problem when an attacker has access to the same network as the email recipient? Or is this kind of sniffing possible across the internet in general?
Current thread:
- Sniffing emails - how? Derek Fountain (Nov 15)
- Re: Sniffing emails - how? Jonathan Kline (Nov 16)
- Re: Sniffing emails - how? xyberpix (Nov 16)
- RE: Sniffing emails - how? Clement Dupuis (Nov 16)
- <Possible follow-ups>
- Re: Sniffing emails - how? miguel . dilaj (Nov 16)
- RE: Sniffing emails - how? Justin Acquaro (Nov 16)
- RE: Sniffing emails - how? Dahate, Pramod (Nov 17)
- RE: Sniffing emails - how? Clement Dupuis (Nov 18)