Subscribe to Windows IT Pro

 

Get Newsletters

  • Get the Latest News
  • Product Updates
  • Helpful Tricks
  • Productivity Tips

Subscribe Now!

August 31, 1997 12:00 AM

Exchange 5.0 POP Psws

Windows IT Pro
InstantDoc ID #9229
Rating: (0)

Exchange 5.0 POP3 Passwords

Reported August 27, 1997 by Rajiv Pant

Systems Affected

Windows NT 4.0 Server running Exchange 5.0 with POP service

The Problem

Exchange 5.0 Server"s POP3 service does not properly expire cached passwords. Therefore, old passwords continue to be valid along with newly set passwords until the cache expires. The same problem can be found in Microsoft"s FTP, HTTP, and Gopher services, as pointed out by David LeBlanc. According to Rajiv Pant, this problem does not affect the new web page interface to get your mail which uses a different authentication. Nor does it affect NT logons.

Stopping the Problem:

Correcting the problem entails adjusting the cache timeout in the Registry.

From the MS KB Article Q166620:

The credentials cache is controlled by the following registry values:


HKLM\System\CurrentControlSet\Services
\MsExchangeIs\ParametersNetIf
\Credentials
Cache Age Limit         (Default  = 120 minutes)

HKLM\System\CurrentControlSet\Services
\MsExchangeIs\ParametersNetIf
\Credentials
Cache Idle Limit                (Default = 15 minutes)

HKLM\System\CurrentControlSet\Services
\MsExchangeIs\ParametersNetIf
\Credentials
Cache Size              (Default = 256 buckets)

Note: to turn off caching, you should set the size = 0

The Age limit specifies the maximum length of time (in minutes) for entries to live in the cache, the Idle limit specifies the amount of idle time after which a credential cache element will be considered too old (and thus discarded).

Microsoft"s Response:

They have been notified, but their response it unknown as of September 1. Perhaps this functionality is by design.

To learn more about new NT security concerns, subscribe to NTSD.

Credit:
Reported by Rajiv Pant
Posted here at NTSecurity.Net August 31, 1997 11am

Related Content:

ARTICLE TOOLS

Comments
    There are no comments to display. Be the first one!
You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

White Papers

Get your Windows 7 deployment off to the right start by implementing PC lockdown. A locked-down environment is easier and cheaper to support since users are less likely to make unnecessary changes to the core system configuration - read more here!

Essential Guides

Is your iSCSI "lossy"? The reality is that most off-the-shelf Ethernet hardware deployed for iSCSI can lose packets, resulting in slow performance or application downtime. Learn how to assess your current iSCSI infrastructure and engineer an advanced iSCSI SAN infrastructure.

Web Seminars

What's the best way to keep your network safe from malware? In this web seminar, security expert Greg Shields suggests an alternative method to the traditional blacklisting approach that is common with anti-virus and anti-malware solutions.

eLearning Series

We bring the experts direct to you to share their real-world perspective and expertise. During each event, three sessions stream in real time, so you can learn, ask questions, and get solutions.
Upcoming event: Getting the Most with Exchange 2010 with Paul Robichaux

Subscribe to Windows IT Pro!

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.