Security Basics mailing list archives

Sniffing emails - how?


From: Derek Fountain <dflists () iinet net au>
Date: Sat, 13 Nov 2004 10:50:12 +0800

Reading the archives of this and other lists, I occasionally come across 
quotes like this (from the WebApp list in this case):

"2/ That sending a user's password in clear text over email systems is a 
secure method; inappropriate for most sites. For example, an attacker could 
provoke the password recovery procedure for his colleague and sniff the email 
containing the password with relative ease."

Am I correct in thinking that this is only a real problem when an attacker has 
access to the same network as the email recipient? Or is this kind of 
sniffing possible across the internet in general?


Current thread: