> If is an exploit to squirrelmail maybe a simple renaming mailto.php > mailtonew.php (and edit al references to mailto.php) can solve temporary this > issue. What is this mailto.php vulnerability of which I've heard so much in this thread? Sounds like something rather nasty. > 2.Use the plugin that draw the password in screen, and i dont know if is > possible disable password field. (if is possible) Which plug in is this? This sounds like it could be useful. ------------------------------------------------------------------------- This SF.net email is sponsored by: Microsoft Defy all challenges. Microsoft(R) Visual Studio 2005. http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/ -- squirrelmail-users mailing list Posting Guidelines: http://www.squirrelmail.org/wiki/MailingListPostingGuidelines List Address: squirrelmail-users@xxxxxxxxxxxxxxxxxxxxx List Archives: http://news.gmane.org/thread.php?group=gmane.mail.squirrelmail.user List Archives: http://sourceforge.net/mailarchive/forum.php?forum_id=2995 List Info: https://lists.sourceforge.net/lists/listinfo/squirrelmail-users