QM Security Hole?
4 messages in this thread
I run Quickmail on my Mac to connect to another company that I work with. I'm a
remote site. The other day, I was talking with another company who was about
to install Quickmail for conversing with their remote employees, too. I
mentioned that we could connect to each other, too.
But they said they'd talked to a local network security firm who said Quickmail
was full of holes, and that they'd be risking their entire Mac network to a
break-in. So this company is going to isolate their Quickmail system from the
network when it's available for dial-up in the evenings, and it won't be
accessible during the day.
I know I was able to demonstrate a "break-in" by using the BBS-like feature to
access any accounts that didn't have a password set. As I pointed out to the
company I work with, that's their own fault for not requiring passwords. Not a
"break-in," just "user stupidity."
But what's this friend-of-a-friend talking about? How could someone gain
access to the rest of the network when they dial in a Quickmail mail center?
Is there a similar state of "RTFM" that could allow this to happen?
Was the "local network security firm" perhaps trying to sell a security product
of some sort? Do they even know what QuickMail is?
We've used QM's gateways for a couple of years, and although we're not
particularly concerned about security here (most of our users have no passwords
either), I don't think it's fair to say it's "full of holes".
The security firm seems to think that QM dial-in gives outsiders complete
access to the network. That's not true at all. It gives access to the E-mail
system only, not to file servers or other machines. There is NO WAY a dial-in
user could interfere with files or get at other devices on the network.
Perhaps the guy is confusing QM with ARA.
In my experience, I have noted only one security problem, and I'm not sure how
it happened. We were experimenting with the modem init strings, and created a
situation where a legitimate user could disconnect without actually logging
out. The next person (potential hacker) who dialed in would resume the
previous user's session without the need to log in or provide a password. But
I don't think that could happen with a properly configured modem.
QM's security is basic, in that it doesn't provide call-back or force users to
use or change passwords. But it's not "full of holes". Unless your E-mail is
full with super-sensitive information, or your company is a prime target for
industrial espionage, I wouldn't worry about it. (Then again, if your friend's
company felt it necessary to hire a "network security firm", maybe they fall
into one of those categories.)
– Ron
Of course, I suspected that, too – but they weren't trying to sell anything,
they just recommended to keep that machine off the net. It made no sense to
me, and it irked me to the point of wanting to track down the
friend-of-a-friend myself.
They didn't hire these people, they just happen to inhabit the same office
building as my friend's. In the case of the company that I demonstrated the
no-password hole, I knew the cheif financial officer was particularly naive, so
I sent them a download of all his messages, which included a dozen people's
salaries and royalties, forecasts, etc.
To whom it may concern:
In response to your E-Mail of 16 Mar 94.
The friend-of-a-friend is wrong. The user dialing into a QM Server would have
access only to QuickMail and its assocaited files. No more, no less.
Your friend-of-a-friend would be correct if they were dialing in with Apple
Remote Access, but not QuickMail.
Sincerely,
Charles K. Davis
Technical Support Rep.
CE Software, Inc.