|
Vulnerability Development
mailing list archives
Re: Academic attacks against RFC 1939, APOP (threat: quite minor)
From: SM <nntp () INAME COM>
Date: Sat, 3 Mar 2001 23:25:03 +0400
At 06:27 01-03-2001 +0100, Bluefish (P.Magnusson) wrote:
Your system clock and your PID is *not* good PRNGs!
That's a good point. When implementing a POP3 server with APOP support,
one should add an element of randomness so that the banner is always
different.
The RFC states:
"The syntax of the timestamp corresponds to the `msg-id' in [RFC822], and
MUST be different each time the POP3 server issues a banner greeting."
-sm
By Date
By Thread
Current thread:
|