Tuesday, March 11, 2008

A security hole in OUTLOOK

Last Saturday, I found a security hole in OUTLOOK . It happened like this. In last Saturday, while I was at the office , one of my friend called me and told to login to his computer and get an email from his OUTLOOK account and tell him the details in that mail. So I tried to login to his computer with his local computer account because he has configured his OUTLOOK account for his local computer account . I tried several times but couldn't login. Then I tried his account for office domain. I could logon by that account but couldn't access required OUTLOOK email account since It was not configured for that user account. So I opened OUTLOOK and tried to open mail file in the mail folder for his local computer account. It said "Access is denied" So I couldn't open it. Then what I did was , copying that file to my Desktop and tried to open it again. Wow, It worked. No messages were prompted saying "Access is denied". It opens without any disturbance.

So If anyone can get a copy of your mail data file(Outlook.pst), He don't need any username, passwords for access your mails. But I think this is somewhat a rare incident. If my friend didn't configured to save his mail data files in a location other than his user "Document and Settings" folder, I might not be able to access that mail data file. So If you have configured OUTLOOK for storing its data in a place that any other user can access without any restrictions, then your emails are vulnerable to read by others. So always try to keep default location for saving your OUTLOOK data files.

0 comments: