Re: [SM-USERS] About new security in SquirrelMail 1.4.20rc2

2009-09-11 Thread Paul Lesniewski
On Fri, Sep 11, 2009 at 11:47 AM, Fernando Gozalo wrote: > El 11/09/09 19:51, Paul Lesniewski escribió: >> On Fri, Sep 11, 2009 at 1:35 AM, Fernando Gozalo  wrote: >>> Hello: >>> >>> Please, consider to change in /src/options.php the line >>> >>> if (!sqgetGlobalVar('smtoken',$submitted_token, SQ_

Re: [SM-USERS] About new security in SquirrelMail 1.4.20rc2

2009-09-11 Thread Fernando Gozalo
El 11/09/09 19:51, Paul Lesniewski escribió: > On Fri, Sep 11, 2009 at 1:35 AM, Fernando Gozalo wrote: >> Hello: >> >> Please, consider to change in /src/options.php the line >> >> if (!sqgetGlobalVar('smtoken',$submitted_token, SQ_POST)) { >> ^

Re: [SM-USERS] About new security in SquirrelMail 1.4.20rc2

2009-09-11 Thread Paul Lesniewski
On Fri, Sep 11, 2009 at 1:35 AM, Fernando Gozalo wrote: > Hello: > > Please, consider to change in /src/options.php the line > > if (!sqgetGlobalVar('smtoken',$submitted_token, SQ_POST)) { >                                                 ^^^ > for > > if (!sqgetGlobalVar('smtoken',$submitted_

[SM-USERS] Group shared mailboxes

2009-09-11 Thread Ahmed, Saqlan
Hi, Do you provide the ability to create and administer share mailboxes? This should have the ability to allow multiple users to login to the mailbox at the same time, much like in Microsoft outlook but we are looking to move away from outlook. Thanks, Saqlan Ahmed | Lehman Brothers Internatio

[SM-USERS] About new security in SquirrelMail 1.4.20rc2

2009-09-11 Thread Fernando Gozalo
Hello: Please, consider to change in /src/options.php the line if (!sqgetGlobalVar('smtoken',$submitted_token, SQ_POST)) { ^^^ for if (!sqgetGlobalVar('smtoken',$submitted_token, SQ_FORM)) { ^^^

Re: [SM-USERS] Squirrel Mail Phish?

2009-09-11 Thread Fredrik Jervfors
> Thanks for the response, but I am still concerned you are missing my > concern. > > It seems that SOMEONE is specifically targeting SquirrelMail web > application users. > > At the very least, admins should know that if the link I provided is > malicious, the chance is high that users are going t