| |
||||||||||||||||||||||||||
|
![]() |
![]() |
![]() |
![]() |
||||||||||||||||||||||
![]() |
![]() |
![]() |
||||||||||||||||||||||||
|
||||||||||||||||||||||||||
| |
SessionGuard
for Outlook Web Access 2000 secures
the user's email system through enhanced logoff technology. SessionGuard
requires no additional hardware, software or databases and is highly
optimized for Exchange 5.5 & 2000 environments.
OWA
has some security issues that should worry Exchange Administrators:
First, an OWA user’s cached credentials can easily be used to
gain unauthorized access to Exchange; and second, because an OWA session
does not time out if the user forgets to logout and close the browser
window, an intruder can gain access to Exchange simply by browsing to
the open OWA session. Most
organizations know to use SSL to encrypt data transferred to and from
the OWA client and the Exchange server, thus making it impossible to
snoop the contents of a user’s email. What most organizations do not
know, however, is SSL will not prevent an intruder from gaining access
to Exchange via an OWA session, even if SSL is used in conjunction with
other security products such as a firewall. This is because OWA relies
on the Web browser for credentials, which are cached. In
short, SessionGuard eliminates the security risk of users unwittingly
exposing Exchange to unauthorized access by blocking and clearing
cached credentials and by allowing an Administrator to define a session
time out.
Copyright © 2001 Messageware Incorporated. All rights reserved.
|
|
||||||||||||||||||||||||
|
||||||||||||||||||||||||||
| |
|
|
|
|
|
|
|
|
|
|
||||||||||||||||