CompuServe Thread

QM Security Hole?

4 messages in this thread
#145801From: SyndesisMar 16, 1994 9:02 AM
I run Quickmail on my Mac to connect to another company that I work with. I'm a remote site. The other day, I was talking with another company who was about to install Quickmail for conversing with their remote employees, too. I mentioned that we could connect to each other, too. But they said they'd talked to a local network security firm who said Quickmail was full of holes, and that they'd be risking their entire Mac network to a break-in. So this company is going to isolate their Quickmail system from the network when it's available for dial-up in the evenings, and it won't be accessible during the day. I know I was able to demonstrate a "break-in" by using the BBS-like feature to access any accounts that didn't have a password set. As I pointed out to the company I work with, that's their own fault for not requiring passwords. Not a "break-in," just "user stupidity." But what's this friend-of-a-friend talking about? How could someone gain access to the rest of the network when they dial in a Quickmail mail center? Is there a similar state of "RTFM" that could allow this to happen?
#145847From: Ron WebbMar 17, 1994 1:07 PM
Was the "local network security firm" perhaps trying to sell a security product of some sort? Do they even know what QuickMail is? We've used QM's gateways for a couple of years, and although we're not particularly concerned about security here (most of our users have no passwords either), I don't think it's fair to say it's "full of holes". The security firm seems to think that QM dial-in gives outsiders complete access to the network. That's not true at all. It gives access to the E-mail system only, not to file servers or other machines. There is NO WAY a dial-in user could interfere with files or get at other devices on the network. Perhaps the guy is confusing QM with ARA. In my experience, I have noted only one security problem, and I'm not sure how it happened. We were experimenting with the modem init strings, and created a situation where a legitimate user could disconnect without actually logging out. The next person (potential hacker) who dialed in would resume the previous user's session without the need to log in or provide a password. But I don't think that could happen with a properly configured modem. QM's security is basic, in that it doesn't provide call-back or force users to use or change passwords. But it's not "full of holes". Unless your E-mail is full with super-sensitive information, or your company is a prime target for industrial espionage, I wouldn't worry about it. (Then again, if your friend's company felt it necessary to hire a "network security firm", maybe they fall into one of those categories.) – Ron
#145848From: SyndesisMar 17, 1994 1:38 PM
Of course, I suspected that, too – but they weren't trying to sell anything, they just recommended to keep that machine off the net. It made no sense to me, and it irked me to the point of wanting to track down the friend-of-a-friend myself. They didn't hire these people, they just happen to inhabit the same office building as my friend's. In the case of the company that I demonstrated the no-password hole, I knew the cheif financial officer was particularly naive, so I sent them a download of all his messages, which included a dozen people's salaries and royalties, forecasts, etc.
#145899From: CE Software, Inc.Mar 18, 1994 5:16 PM
To whom it may concern: In response to your E-Mail of 16 Mar 94. The friend-of-a-friend is wrong. The user dialing into a QM Server would have access only to QuickMail and its assocaited files. No more, no less. Your friend-of-a-friend would be correct if they were dialing in with Apple Remote Access, but not QuickMail. Sincerely, Charles K. Davis Technical Support Rep. CE Software, Inc.