Bugtraq mailing list archives

Re: Not so much a bug as a warning of new brute force attack


From: Albert-Lunde () nwu edu (Albert Lunde)
Date: Tue, 4 Jun 1996 19:50:41 -0500


My solution was to decouple the POP passwords from the account
passwords by having a separate POP password file.

However, isn't there a safer way of sending passwords over the network?

There's the APOP extension which uses MD5 hashes, and I think another
which allows use of any IMAP autorization extension, plus there is
some sort of kerberized pop. (I think commercial Eudora supports
APOP and kerberos.)

--
    Albert Lunde                      Albert-Lunde () nwu edu



Current thread: