[[email protected]: Bug#198843: very chatty with password information]

Guido Trotter <[email protected]>
Newsgroups gmane.network.directoryadmin
Message-ID <[email protected]>
Hi,

I received this request from a Debian user not to disclose the user
password, when displaying the user information, since the X console may be
logged somewhere.
I agree with him, but I'd rather implement it simply displaying some fake
token instead of the actual password, and not actually commenting out the
debugging information. Perhaps DA could write something like

password: ******** (actual password not displayed)

If you concur with my solution I can write a patch to address this. If you
have a better idea please tell me. :)

Bye, and Thanks,

Guido

----- Forwarded message from Jamie Wilkinson <[email protected]> -----

Subject: Bug#198843: very chatty with password information
Resent-Message-ID: <[email protected]>
X-Debian-PR-Message: report 198843
X-Debian-PR-Package: directory-administrator
X-Debian-PR-Keywords: security
Date: Thu, 26 Jun 2003 13:29:00 +1000
From: Jamie Wilkinson <[email protected]>
To: [email protected]

Package: directory-administrator
Version: 1.5.1-4
Tags: security
Severity: normal

d-a protects passwords with the ol' **** prompt in the interface, but happily
spews out the password entered in various locations to the console.  When
running from an X menu, who knows where console output may be logged?

For example:

get_group_cn_list: filtering entries for groups' CNs
Keypress on modify user dialog xxx (x) state 16
...
...
set password called with password: xxxxxx
set password set attribute: xxxxxx

...

Entry was modified.  Changes follow:
LDAP_MOD_DELETE objectclass
        account
LDAP_MOD_REPLACE userPassword
         xxxxxx
LDAP_MODE_REPLACE authPassword
         xxxxxxx

...

Called process preferences dialog
password type md5sum(null)set password called with password
set password set attribute: {crypt}$1$...

and so on.  (actual password components replaced with x)

It would be really nice if d-a didn't include password information as part of
the debugging output at all -- I suggest whereever the code is printing the
password, that code just be commented out (unless there's a better way to
disable this "feature").

Jamie

----- End forwarded message -----

-- 
Guido Trotter
Jabber ID: [email protected]
Public PGP key available on: http://www.cs.unibo.it/~trotter/



-------------------------------------------------------
This SF.Net email is sponsored by: INetU
Attention Web Developers & Consultants: Become An INetU Hosting Partner.
Refer Dedicated Servers. We Manage Them. You Get 10% Monthly Commission!
INetU Dedicated Managed Hosting http://www.inetu.net/partner/index.php
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.