Forum Moderators: DixonJones

Message Too Old, No Replies

iMail Referral Strings

Security Breech Discovered

         

pageoneresults

3:48 pm on Aug 1, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



I'm hoping this is the right forum to post this in since it has to do with referral strings.

I normally check my email using two different methods. From the home office, all mail is delivered directly into my mail program (Outlook Express).

From the Corporate office, we have Microsoft Exchange Server and I check other email accounts via a web-based email program from ipswitch called iMail. This is the same program that my host uses for client email hosting.

Yesterday, 2002 July 31, I was communicating with someone concerning a URL Submission to our directory. When I'm checking mail via the web based program, I usually follow links from within the email so the referrer string shows us reviewing that site in that persons referrer logs.

Well, this person happen to be looking at their live referrer logs, noticed the referring URL and clicked it. Viola, they went straight into my web based email system. Normally they would end up at the login screen, but not this time. I guess it had something to do with my still being logged in and them clicking the link before a session expired, I'm not sure yet.

For those of you who may be using the ipswitch iMail product, you may want to look into this. This is the first time in the 3+ years that I've been using it that a problem has surfaced. I wonder how many others were able to access my email via the referring URL!

We are contacting ipswitch this morning to discuss the issue. In the mean time, for those of you using the program, there may be a security breech if someone follows a link in an email from their web based login. I think the timing has to be just right for this to happen. I'll come back and post more as we figure out what the problem is.

P.S. I don't keep anything in my web based email program for more than 12 hours. It is not used as a storage facility, more as a gateway while I'm away from the home office.

evinrude

6:56 pm on Aug 1, 2002 (gmt 0)

10+ Year Member



Dunno if this helps, but IPSwitch released version 7.12 today with some patches, including a fix to a buffer overflow.

Additional info here [support.ipswitch.com]

pageoneresults

7:00 pm on Aug 1, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Thanks evinrude, I forwarded that link to my tech, much appreciated!

Birdman

7:29 pm on Aug 1, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Yes, I believe someone is getting into my imail account too. I've been getting email with return addresses of our real customers who are still in the system. These e-mails contain files with extensions like .exe and .bat and others. They have subject lines like "This is my first game", "bordercolor", "here to visit", and many others. I just contacted our host and am waiting for a reply. I think they are also sending these e-mails out to any e-mail address in our system using our e-mail address. I'm not happy, to say the least. :(