Firewall Wizards mailing list archives

Re: POP3 Security Issues


From: dreamwvr <dreamwvr () dreamwvr com>
Date: Mon, 30 Nov 1998 11:40:34 -0700

hi,
  is there a gnu freely available APOP server for linux, and Solaris2.x.x ???
if so does anyone know a reliable url to try it out. Also is netscape 4.x and 
Eudora 3.xx compliant to APOP server standard?
                                                        Regards,
                                                                dreamwvr () dreamwvr com
At 01:10 PM 11/27/98 -0500, Frederick M Avolio wrote:
At 08:55 AM 11/16/98 -0500, mreiter () gwillness osd mil wrote:
My users want to use POP3 over the internet to access their e-mail through
our firewall.  There is a POP3 proxy built in to the firewall (not
currently on), but I am leery of ANY access through the firewall over the
internet.  Does anyone know of security issues surrounding this?

1. Their email will be visible as it flows over the Internet. An encrypted
connection protects this.

2. Their reusable password will be visable over the Internet unless you use
APOP authentication (not bulletproof, but better than a reusable password).

3. They must be educated against using the usual PC email stations at
conferences. These are wonderful places to find all sorts of email left
behind by people who both sent and received email using them.

Fred
Avolio Consulting
16228 Frederick Road, PO Box 609, Lisbon, MD 21765
410-309-6910 (voice)           410-309-6911 (fax)
http://www.avolio.com


Reuters, London, February 29, 1998: 
Scientists have announced discovering a meteorite which will strike the 
earth in March, 2028.  Millions of UNIX coders expressed relief for being 
spared the UNIX epoch "crisis" of 2038.
_______________________________________________________________________

DREAMWVR.COM - TOTAL WEB INTEGRATION, DEVELOPMENT, DESIGN SERVICES. 
Featuring Website Development and Web Strategies of a TOP Developer 
<http://www.dreamwvr.com/dynamicduo.html> <mailto:dreamwvr () dreamwvr com>
"As Unique as the Company You Keep."        "===0 PGP Key Available  
________________________________________________________________________
                                                                   




Current thread: