[SM-USERS] Disable Autocomplete

2012-07-13 Thread res5it
Hi all.. Durring security scan of my webmail, I get the following vuln: Synopsis: Auto-complete is not disabled on password fields. 

Description
The remote web server contains at least HTML form field containing an input of type 'password' where 'autocomplete' is not set to 'off'. 

While this

Re: [SM-USERS] Disable PHP's 'register_globals' setting

2009-04-05 Thread res5it
Thanx for your reply... I know that some times nessus is produsing false positives , but in this case I was not sure.. Any other suggestions maybe? Best Regards -- View this message in context: http://www.nabble.com/Disable-PHP%27s-%27register_globals%27-setting-tp22493467p22532965.html Sent f

[SM-USERS] Disable PHP's 'register_globals' setting

2009-03-15 Thread res5it
Hi all, i need some help I did scan of my network with nessus and i get the following warning: Description : The version of SquirrelMail installed on the remote fails to check the origin of the 'base_uri' parameter in the 'functions/strings.php' script before using it to set the path for its co