home
***
CD-ROM
|
disk
|
FTP
|
other
***
search
/
Freaks Macintosh Archive
/
Freaks Macintosh Archive.bin
/
Freaks Macintosh Archives
/
Security⁄Insecurity
/
Eudora
/
eudora-script.txt
Wrap
Text File
|
1999-04-30
|
1KB
|
35 lines
<--> File was taken from the Mac MNGRs mailing list, a good note!
<--> Redistributed for security issues on Mac Security Site.
Eudora has a security hole - try using this AppleScript:
<bold><fontfamily><param>Geneva</param>tell</fontfamily></bold><fontfamily><param>Geneva</param>
application "Eudora Pro" <bold>to get</bold> setting 31
</fontfamily>For Eudora Pro substitute Eudora Lite or whatever you use
(it will ask you to locate your Eudora, anyway).
Lo and behold - your password in plaintext!!
I can't write JavaScript but presumably someone could write one to send
that information back.
Vince
</excerpt>
I tested this and sure enough it pulled my almost hacker proof password
and showed it in the output window. I passed this info on to an
internal mailing list here at USCD and someone responded that this hack
only works if you have the "Save Password" box checked in the Eudora
settings (I verified this to be true), it won't even work if you
entered your password and it is residing in memory. Shortly there
after, I recieved an email from the VP of Technology at Qualcomm
(obviously someone sent him my email) and he was kind enough to answer
questions about this new hack as well as my original questions.
Oh, while writing up this summary I got another incoming email from
someone here on campus and he had this to say about my response from
Steve Dorner.