Re: Security hole?

"Graham Leggett" <[email protected]> Tue, 25 Jan 2005 09:51:46 +0200 (SAST)
Newsgroups gmane.network.directoryadmin
Message-ID <[email protected]>
Ryan Golhar said:

> The program creates a directory called .directory_administrator which
> contains a file called profiles which contains information on connecting
> to the LDAP server.  It stores the password used for connecting in clear
> text.
>
> The file itself has group,world read permissions, however the directory
> does not.
>
> Since I use the root acocunt to connect to the ldap directory, I tend to
> consider this a security hole as the password is in plain view should
> anyone gain access to my account...

If somebody gained access to the root account, they could gain access to
the LDAP server database (if stored locally), or they could trojan the
directory_administrator binary, or they could sniff the LDAP connection
(if clear text) for the password, the password stored is the least of your
problems.

However software that stores passwords locally should warn the user that
this is happening, and allow the user the option to not save the password
locally if the user so chooses. Your concern is definitely valid - where
an end user is not comfortable with saving passwords to disk, they should
be given the option not to.

Regards,
Graham
--



-------------------------------------------------------
This SF.Net email is sponsored by: IntelliVIEW -- Interactive Reporting
Tool for open source databases. Create drag-&-drop reports. Save time
by over 75%! Publish reports on the web. Export to DOC, XLS, RTF, etc.
Download a FREE copy at http://www.intelliview.com/go/osdn_nl