mik 2 #1 August 19, 2006 I have not searched to see if this has already been reported / discussed, but use of the Internet Explorer 'History' option can show at least your mail inbox - I have not tried to see whether the contents of your mails can be read in this way..... Pretty poor security IMO *********************************************** I'm NOT totally useless... I can be used as a bad example Quote Share this post Link to post Share on other sites
stratman05 0 #2 September 4, 2006 I'm gonna go out on a limb and say you checked the "remember me" checkbox at login? Or your session never ended. If so, this set the cookie to remember your login info. When you are clicking through your history, the cookie logs you back in and goes to your email. The link in the history is nothing special...it's just a link. If your didn't log out or kill the session, then it's just like clicking a link in the site. I won't explain all the backend stuff, but I'm 99.9% positive this is the case, unless you can prove otherwise b/c this is a huge exploit. Maybe it's not "pretty poor security'. maybe it's "not informed user"? Quote Share this post Link to post Share on other sites
mik 2 #3 September 29, 2006 Remember me is never clicked Session is always killed and I have experienced this on a number of different computers - history file always shows email headers etc... *********************************************** I'm NOT totally useless... I can be used as a bad example Quote Share this post Link to post Share on other sites
PhreeZone 20 #4 September 30, 2006 It took me a while to put together what you are saying. Basically the subject line gets included in the title tag for mail so that when you look at the top of the IE window it now says the subject. Hotmail says "MSN Hotmail - Message" for the same thing. It does not put the subject in the title tag. GMail uses AJAX so none of the mail history appears in the history. Not sure about Yahoo or anything else. Emails are unreadable still as long as you are clearing the cache after you log out, but the subject line is visable unless the history is cleared also. Not sure how big of a security issue it is, no one can read the emails but they can see the subject.Yesterday is history And tomorrow is a mystery Parachutemanuals.com Quote Share this post Link to post Share on other sites
CaptainOKaos 0 #5 December 5, 2006 What service are you using to log on to DZ ? AOL, MSN, Do you have Windows XP ? With this I could better advice you on how to prevent this problem in the future.You're as wonderful as a slinkie!! NOT REALLY GOOD FOR ANYTHING BUT THEY BRING A SMILE TO YOUR FACE WHEN PUSHED DOWN THE STAIRS. Quote Share this post Link to post Share on other sites
stratman05 0 #6 December 8, 2006 It's b/c the html tag has "Dropzone.com: [Message Title]" in it... nothing else is viewable. If they change it to remove the subject from the title tag, it will jsut day "Dropzone.com". Quote Share this post Link to post Share on other sites