Likes Likes:  0
Resultaten 1 tot 3 van de 3
Geen
  1. #1
    Marc Ruef
    Netscape Communicator 4.x sensitive informations in configuration file
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Netscape Communicator 4.x sensitive informations in configuration file

    Hi!

    It seems that I'm one of the last Netscape 4.x users. During my research
    for using roaming profiles I've checked a file named prefs.js in my
    netscape folder (C:\Program Files\Netscape\Users\mruef).

    The following paste shows the IMAP mail part of this configuration file.
    You can see that the line 17 shows the unencrypted password
    ("MyPassword4").

    --- cut ---

    user_pref("mail.imap.server.imap.computec.ch.admin _url", "");
    user_pref("mail.imap.server.imap.computec.ch.capab ility", 4641);
    user_pref("mail.imap.server.imap.computec.ch.check _new_mail", true);
    user_pref("mail.imap.server.imap.computec.ch.check _time", 60);
    user_pref("mail.imap.server.imap.computec.ch.clean up_folders_on_exit",
    false);
    user_pref("mail.imap.server.imap.computec.ch.clean up_inbox_on_exit",
    false);
    user_pref("mail.imap.server.imap.computec.ch.delet e_model", 2);
    user_pref("mail.imap.server.imap.computec.ch.dual_ use_folders", true);
    user_pref("mail.imap.server.imap.computec.ch.empty _trash_on_exit",
    false);
    user_pref("mail.imap.server.imap.computec.ch.empty _trash_threshhold",
    0);
    user_pref("mail.imap.server.imap.computec.ch.isSec ure", true);
    user_pref("mail.imap.server.imap.computec.ch.names pace.other_users",
    "");
    user_pref("mail.imap.server.imap.computec.ch.names pace.personal",
    "\"INBOX.\"");
    user_pref("mail.imap.server.imap.computec.ch.names pace.public",
    "\"shared.\"");
    user_pref("mail.imap.server.imap.computec.ch.offli ne_download", false);
    user_pref("mail.imap.server.imap.computec.ch.overr ide_namespaces",
    true);
    user_pref("mail.imap.server.imap.computec.ch.passw ord", "MyPassword4");
    user_pref("mail.imap.server.imap.computec.ch.remem ber_password", true);
    user_pref("mail.imap.server.imap.computec.ch.serve r_sub_directory", "");
    user_pref("mail.imap.server.imap.computec.ch.userN ame", "mruef");
    user_pref("mail.imap.server.imap.computec.ch.using _subscription", true);

    -- cut ---

    This is also true for POP3 and perhaps for SMTP, NNTP and LDAP
    passwords. The passwords are only stored if the remember password option
    is set (e.g. line 18).

    It may be possible to extract these passwords during a sneaking access
    to the system (local or remote by a backdoor)[1, 2] or examine a backup.
    This weakness should be keeped in mind.

    I'm not sure if this vulnerability exists in other Netscape versions
    (e.g. 6 or 7).

    Bye, Marc

    [1] http://www.idefense.com/advisory/11.19.02c.txt
    [2] http://www.securityfocus.com/bid/6215

    --
    Computer, Technik und Security http://www.computec.ch/
    Meine private Webseite http://www.computec.ch/mruef/

  2. #2
    Paul Szabo
    Netscape Communicator 4.x sensitive informations in configuration file
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: Netscape Communicator 4.x sensitive informations in configuration file

    Byron York <byron@benefitrecovery.com> wrote:

    >> ... I've checked a file named prefs.js ...
    >> the IMAP mail part ... shows the unencrypted password ...
    >>
    >> user_pref("mail.imap.server.imap.computec.ch.passw ord", "MyPassword4");
    >> user_pref("mail.imap.server.imap.computec.ch.remem ber_password", true);
    >>
    >> This is also true for POP3 and perhaps for SMTP, NNTP and LDAP
    >> passwords. The passwords are only stored if the remember password option
    >> is set (e.g. line 18).
    >>
    >> It may be possible to extract these passwords during a sneaking access
    >> to the system (local or remote by a backdoor)[1, 2] or examine a backup.
    >> This weakness should be keeped in mind.
    >>
    >> I'm not sure if this vulnerability exists in other Netscape versions
    >> (e.g. 6 or 7).
    >>
    >> [1] http://www.idefense.com/advisory/11.19.02c.txt
    >> [2] http://www.securityfocus.com/bid/6215

    >
    > We use Netscape 4.74 with roaming profiles using POP3, and my prefs.js file
    > keeps the password hidden:
    >
    > user_pref("mail.pop_name", "byron");
    > user_pref("mail.pop_password", "encryptedstuff");
    > user_pref("mail.remember_password", true);
    >
    > I am not sure if the encryption is turned on someplace, but I suspect it is
    > on by default, for it is definitely there for all of our POP clients using
    > 4.74.


    That is not encryption, but reversible obfuscation. Look in the Netscape
    source code for how to decode that: Netscape is able to do it and send the
    clear-text password to the POP server.

    Do not allow Netscape (or other utilities, e.g. Eudora) to remember your
    passwords.

    Cheers,

    Paul Szabo - psz@maths.usyd.edu.au http://www.maths.usyd.edu.au:8000/u/psz/
    School of Mathematics and Statistics University of Sydney 2006 Australia

  3. #3
    Neil Dickey
    Netscape Communicator 4.x sensitive informations in configuration file
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: Netscape Communicator 4.x sensitive informations in configuration file


    Marc Ruef <marc.ruef@computec.ch> wrote:

    >The following paste shows the IMAP mail part of this configuration file.
    >You can see that the line 17 shows the unencrypted password
    >("MyPassword4").
    >
    >[ ... Snip ... ]
    >
    >user_pref("mail.imap.server.imap.computec.ch.pass word", "MyPassword4");
    >user_pref("mail.imap.server.imap.computec.ch.reme mber_password", true);


    I notice from the line immediately following that you have the package
    remember your password. It's been my understanding that doing so is
    bad practice because that's just the sort of thing that someone probing
    your system would very likely be looking for. Certainly if you save
    your password only in your head, then whether or not the program stores
    it in the clear is a moot question. ;-)

    Best regards,

    Neil Dickey, Ph.D.
    Research Associate/Sysop
    Geology Department
    Northern Illinois University
    DeKalb, Illinois
    60115

Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics