For instance popmail.libero.it is quite weird, this is what happens:
- - When the username is wrong the server replies with and expected:
+ - When the username is wrong the server replies with an expected:
-ERR [AUTH] invalid user or password
- When the username is right but the password is wrong the server replies
- with an information-leaking:
+ with a different message:
-ERR ERROR 119 invalid user or password err 30