Re: Users can login with old passwords!

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On 06/22/2010 11:34 AM, Dogsbody wrote:
>
> Please help, I have been all over google and the archives but cannot see
> this discussed anywhere.
>
> Standard LAMP server (details below), login to squirrelmail, fine,
> logout.  Change users password and log back into squirrelmail using old
> password!!  Logout and login with new password too!
>
> I have lots of data but not sure what is relevant.
>
> It looks like squirrelmail is holding onto the IMAP login as I don't see
> it disconnect when the user logs out.  In fact, when they login with the
> old password I don't see the authentication passed through to the IMAP
> server so I am guessing squirrelmail is caching something locally!?
>
> I thought this may be a session issue but after changing the users
> password I can login using the old password on a separate browser with
> cleared cookies :-/
>
> Any help gratefully received.  Details of my environment are below...
>
> SquirrelMail version : 1.4.20
> Installed Plugins    : squirrelspell, delete_move_next, message_details
> PHP version          : 5.2.0
> Web server  : Apache 2.0.52
> IMAP server : Dovecot 1.1.8
> SMTP server : Sendmail 8.13.1
> OS          : CentOS 4.5
> Installed from tarball
> Browsers    : Firefox 3.5&  Safari 5.0
> Shout if you need any more info.

Are you running an IMAP Proxy?  up-imapproxy, specifically, would still 
work with the old password as long as an existing connection remained 
cached.

HTH,

Dave
-- 
Dave McMurtrie, SPE
Email Systems Team Leader
Carnegie Mellon University,
Computing Services

------------------------------------------------------------------------------
ThinkGeek and WIRED's GeekDad team up for the Ultimate 
GeekDad Father's Day Giveaway. ONE MASSIVE PRIZE to the 
lucky parental unit.  See the prize list and enter to win: 
http://p.sf.net/sfu/thinkgeek-promo
-----
squirrelmail-users mailing list
Posting guidelines: http://squirrelmail.org/postingguidelines
List address: squirrelmail-users@xxxxxxxxxxxxxxxxxxxxx
List archives: http://news.gmane.org/gmane.mail.squirrelmail.user
List info (subscribe/unsubscribe/change options): https://lists.sourceforge.net/lists/listinfo/squirrelmail-users


[Index of Archives]     [Video For Linux]     [Yosemite News]     [Yosemite Photos]     [gtk]     [KDE]     [Cyrus SASL]     [Gimp on Windows]     [Steve's Art]     [Webcams]

  Powered by Linux