Welcome, Guest. Please login or register.
October 07, 2008, 11:59:40 AM

Login with username, password and session length

197854 Posts
22774 Topics
54726 Members

Latest Member: zlat

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Backup
| | |-+  Help
| | | |-+  SMTP password!!!!
« previous next »
Pages: [1] Go Down Print
Author Topic: SMTP password!!!!  (Read 2159 times)
panic
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5451


... and I say to myself, "What a wonderful world"


« on: July 30, 2006, 08:30:35 PM »

Hey all,

I just noticed that your SMTP password, as entered in the Comodo Backup job parameters, is stored in the registry in PLAIN TEXT right next to the username!!!!! All a spammer needs to do is spoty this and do a bit of mining and they've got all the details to hijack and use your email account for spamming.

Bad Comodo! BAD!

Possible to encrypt? Maybe use a password on the app as a decrypt key?

Really needs to be looked at.

Ewen :-(
Logged

As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the  Comodo Forum Policy.
If you don't like it, don't use the forum.
Paulo
Comodo's Hero
*****
Offline Offline

Posts: 391


« Reply #1 on: July 31, 2006, 09:19:00 AM »

Ewen: Tx - forwarded on to devs.
Logged
umesh
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 312



WWW
« Reply #2 on: July 31, 2006, 09:25:35 AM »

Thanks for highlighting it Panic
Soon we are coming up with an update on Comodo BackUp side, will take care of it.
Logged
panic
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5451


... and I say to myself, "What a wonderful world"


« Reply #3 on: July 31, 2006, 09:43:41 AM »

Thanks for highlighting it Panic
Soon we are coming up with an update on Comodo BackUp side, will take care of it.

Glad to hear it. Updating to CPF or CAVS style GUI at the same time?

Ewen :-)
Logged

As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the  Comodo Forum Policy.
If you don't like it, don't use the forum.
HHH
Comodo Member
**
Offline Offline

Posts: 40


« Reply #4 on: August 07, 2006, 05:11:24 AM »

Hey all,

I just noticed that your SMTP password, as entered in the Comodo Backup job parameters, is stored in the registry in PLAIN TEXT right next to the username!!!!! All a spammer needs to do is spoty this and do a bit of mining and they've got all the details to hijack and use your email account for spamming.

Bad Comodo! BAD!

Possible to encrypt? Maybe use a password on the app as a decrypt key?

Really needs to be looked at.

Ewen :-(

Hi panic

have u checked this, In the Email notify without providing the password also the mail is sent to the recipient mail address. Due to this the security is very very less :Smiley. Instead the comodo people could provide a default smtp mail id from which the mail could be sent to the recipient
 Jiggy
Logged

With Regards
   HHH

(\__/)
(='.'=) This is Bunny. Copy and paste Bunny into your
('')_('') signature to help him gain world domination!
panic
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5451


... and I say to myself, "What a wonderful world"


« Reply #5 on: November 01, 2007, 03:54:59 PM »

Thanks for highlighting it Panic
Soon we are coming up with an update on Comodo BackUp side, will take care of it.

Problem still exists in V1.0.2

Ewen :-)
Logged

As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the  Comodo Forum Policy.
If you don't like it, don't use the forum.
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.284 seconds with 19 queries.
Powered by SMF 1.1.5 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com