Old mail passwords still working after update (courier)

  • a user told me he have setup a mail password with a special sign which is used or reserved for PHP ....
    like ; or '


    than he changed the old password again
    fex:
    cTf5kkxad; (old)
    cTf5kkx99 (new)


    and now he say he was able to login with both passwords ???

  • Tested and can't confirm. Where has the user changed his password? In roundcube or imscp interface?

  • It is possible ... he send me to different passwords for one mail account and I was able to login with both !
    I'm still waiting for response because of the question how and where he set-up the passwords.

  • Question:


    Only possible to login on roundcube with both passwords? Or also possible to connect to IMAP server with external client such as outlook with both passwords? It's not the same thing. In first case, it's surely because the old password data has not been removed from the roundcube database. In the second case, this become more critical...

    badge.php?id=1239063037&bid=2518&key=1747635596&format=png&z=547451206

  • Re;


    You are using Dovecot or Courier?

    badge.php?id=1239063037&bid=2518&key=1747635596&format=png&z=547451206

  • Also please, what is the result of the following command:


    Shell-Script
    1. # sasldblistusers2 | grep [email protected]


    Of course, you must replace [email protected] by your data.

    badge.php?id=1239063037&bid=2518&key=1747635596&format=png&z=547451206