OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Steve Sobol (securitySteveSobol.com)
Date: Mon Jan 07 2002 - 14:04:23 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    At 11:08 AM 1/7/2002 -0500, you wrote:

    >For me, the only ultimate security solution comes down to not using OWA.
    >This eliminates OWA based exploits and IIS/system level based exploit caused
    >by IIS. This would require me to get users going on dial-ups,VPNs, or
    >POP3/IMAP, all which have tradeoffs.

    Tradeoffs, yes, but have you considered IMAP-aware webmail? Microsoft Exchange
    speaks IMAP. I've used various non-Microsoft email clients with Exchange
    mailboxen
    with no problem.

    That'll be the closest you can get to OWA without actually using OWA and there
    are plenty of webmail packages out there for various platforms.

    JustThe.net LLC - Steve "Web Dude" Sobol, CTO ICQ: 56972932/WebDude216
    website: http://JustThe.net email: sjsobolJustThe.net phone: 216.619.2NET
    postal: 5686 Davis Drive, Mentor On The Lake, OH 44060-2752 DalNet: ZX-2