Hash method for passwords in configuration backup

Use this forum if you have installed hMailServer and want to ask a question related to a production release of hMailServer. Before posting, please read the troubleshooting guide. A large part of all reported issues are already described in detail here.
Post Reply
Gene
New user
New user
Posts: 2
Joined: 2021-05-17 03:14

Hash method for passwords in configuration backup

Post by Gene » 2021-05-17 03:21

Howdy,

What hashing mechanism does hMailServer 5.6.4-B2283 use for storing user (mailbox) credentials?

Some background:

I'm preparing to migrate accounts from a hMailServer 5.6.4-B2283 installation to a Linux based one. I've been running a packet capture on this host to collect credentials for this move.

I'd like to speed up the process by attempting to guess the passwords that are stored in the XML file when doing a configuration backup. I don't want to run any brute force attempts against the POP3 server as it's running on very old hardware and software, I don't want to flood the logs, and I'd like to avoid mucking up the LastLoginTime field on the accounts.

Thanks in advance for any help!

User avatar
mattg
Moderator
Moderator
Posts: 21450
Joined: 2007-06-14 05:12
Location: 'The Outback' Australia

Re: Hash method for passwords in configuration backup

Post by mattg » 2021-05-17 03:49

you can't 'get' the current password

You can re-set all passwords to a known password
https://www.hmailserver.com/documentati ... e_password
Just 'cause I link to a page and say little else doesn't mean I am not being nice.
https://www.hmailserver.com/documentation


Gene
New user
New user
Posts: 2
Joined: 2021-05-17 03:14

Re: Hash method for passwords in configuration backup

Post by Gene » 2021-05-17 19:54

This looks like what I need. Thanks!

Post Reply