Security hole?

"Ryan Golhar" <[email protected]> Mon, 24 Jan 2005 18:01:43 -0500
Newsgroups gmane.network.directoryadmin
Organization UMDNJ
Message-ID <00d301c50268$ac69db00$c000a8c0@GOLHARMOBILE1>
The program creates a directory called .directory_administrator which
contains a file called profiles which contains information on connecting
to the LDAP server.  It stores the password used for connecting in clear
text.  

The file itself has group,world read permissions, however the directory
does not.  

Since I use the root acocunt to connect to the ldap directory, I tend to
consider this a security hole as the password is in plain view should
anyone gain access to my account...

Ryan



-------------------------------------------------------
This SF.Net email is sponsored by: IntelliVIEW -- Interactive Reporting
Tool for open source databases. Create drag-&-drop reports. Save time
by over 75%! Publish reports on the web. Export to DOC, XLS, RTF, etc.
Download a FREE copy at http://www.intelliview.com/go/osdn_nl