Ideas

Sander Striker s.striker at striker.nl
Sun Mar 5 14:41:01 GMT 2000


Hi,

>This might be out of place but I have a problem that I think samba 
>can solve
>but IM not sure.  I want to validate incoming smtp and pop3 services in
>linux against an NT4sp4 PDC.  Any ideas.

Yes, don't do it. Ofcourse you can as someone suggested with a pam aware
pop3 server. The problem is that pop3 sends username/password combinations
in the clear over the wire. One network sniffer and security for a user
that checks his mail remotely is compromised. Please consider this before
implementing this.
The reason why I get upset when I see this, is because at the university
here, the same scheme was used and some students hacked up a little
program which did just this, sniff for pop3 connections and record the
username/password combination. This was detected after one day, which
is a long period of time in which a lot of mail was checked...

Sander Striker




More information about the samba-ntdom mailing list