Hi!
It seems that I'm one of the last Netscape 4.x users. During my research
for using roaming profiles I've checked a file named prefs.js in my
netscape folder (C:\Program Files\Netscape\Users\mruef).
The following paste shows the IMAP mail part of this configuration file.
You can see that the line 17 shows the unencrypted password
("MyPassword4").
--- cut ---
user_pref("mail.imap.server.imap.computec.ch.admin _url", "");
user_pref("mail.imap.server.imap.computec.ch.capab ility", 4641);
user_pref("mail.imap.server.imap.computec.ch.check _new_mail", true);
user_pref("mail.imap.server.imap.computec.ch.check _time", 60);
user_pref("mail.imap.server.imap.computec.ch.clean up_folders_on_exit",
false);
user_pref("mail.imap.server.imap.computec.ch.clean up_inbox_on_exit",
false);
user_pref("mail.imap.server.imap.computec.ch.delet e_model", 2);
user_pref("mail.imap.server.imap.computec.ch.dual_ use_folders", true);
user_pref("mail.imap.server.imap.computec.ch.empty _trash_on_exit",
false);
user_pref("mail.imap.server.imap.computec.ch.empty _trash_threshhold",
0);
user_pref("mail.imap.server.imap.computec.ch.isSec ure", true);
user_pref("mail.imap.server.imap.computec.ch.names pace.other_users",
"");
user_pref("mail.imap.server.imap.computec.ch.names pace.personal",
"\"INBOX.\"");
user_pref("mail.imap.server.imap.computec.ch.names pace.public",
"\"shared.\"");
user_pref("mail.imap.server.imap.computec.ch.offli ne_download", false);
user_pref("mail.imap.server.imap.computec.ch.overr ide_namespaces",
true);
user_pref("mail.imap.server.imap.computec.ch.passw ord", "MyPassword4");
user_pref("mail.imap.server.imap.computec.ch.remem ber_password", true);
user_pref("mail.imap.server.imap.computec.ch.serve r_sub_directory", "");
user_pref("mail.imap.server.imap.computec.ch.userN ame", "mruef");
user_pref("mail.imap.server.imap.computec.ch.using _subscription", true);
-- cut ---
This is also true for POP3 and perhaps for SMTP, NNTP and LDAP
passwords. The passwords are only stored if the remember password option
is set (e.g. line 18).
It may be possible to extract these passwords during a sneaking access
to the system (local or remote by a backdoor)[1, 2] or examine a backup.
This weakness should be keeped in mind.
I'm not sure if this vulnerability exists in other Netscape versions
(e.g. 6 or 7).
Bye, Marc
[1] http://www.idefense.com/advisory/11.19.02c.txt
[2] http://www.securityfocus.com/bid/6215
--
Computer, Technik und Security http://www.computec.ch/
Meine private Webseite http://www.computec.ch/mruef/

Likes:

Quote