Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Vulnerability Development: Re: Academic attacks against RFC 1939, APOP (threat: quite minor)

Re: Academic attacks against RFC 1939, APOP (threat: quite minor)

From: SM <nntp_at_INAME.COM>
Date: Sat, 3 Mar 2001 23:25:03 +0400

At 06:27 01-03-2001 +0100, Bluefish (P.Magnusson) wrote:
>Your system clock and your PID is *not* good PRNGs!

That's a good point. When implementing a POP3 server with APOP support,
one should add an element of randomness so that the banner is always
different.

The RFC states:

"The syntax of the timestamp corresponds to the `msg-id' in [RFC822], and
MUST be different each time the POP3 server issues a banner greeting."

-sm
Received on Mar 03 2001

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]