home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.sys.sun.admin,comp.security
- Path: sparky!uunet!psgrain!hippo!ucthpx!dip1!fred
- From: fred@dip1.ee.uct.ac.za (Fred Hoare)
- Subject: FTP logging - security weakness?
- Sender: news@ucthpx.uct.ac.za (UCT News Admin.)
- Message-ID: <fred.716034444@dip1>
- Date: 9 Sep 92 10:27:24 GMT
- Organization: University of Cape Town
- Keywords: ftp,security
- Lines: 18
-
- Hi
-
- I was playing around with the logging options of
- Sun's ftpd daemon (SunOs 4.1.2) and discovered that
- the log files contained the passwords that were typed
- in by the ftp users.
- This seems to me to be a big security hole even though
- the log files can be set to be readable by root only.
- Is this a bug in Sun's ftp daemon or are the log
- files supposed to contain the passwords?
- By the way I haven't checked to see if the telnet
- logfiles do this as well.
-
- --
- Frederick Hoare email: fred@dip1.ee.uct.ac.za
- Image Processing Laboratory
- Department of Electrical and Electronic Engineering
- University of Cape Town, South Africa
-