Astaro User Bulletin Board
Go Back   Astaro User Bulletin Board > Closed Forums (read only) > ASG V7.200 BETA (closed)

Welcome to the Astaro User Bulletin Board.
If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

 
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 05-21-2008, 09:07 PM
Wolperdinger's Avatar
Junior Member
 
Join Date: Sep 2005
Posts: 20
Angry 7.193: emailpki_debug.log stores credentials in plane ascii text

Hi folks,

when playing around with the files in /tmp I had to discover that emailpki_debug.log stores diffent credentials in plain ascii text.

Starting with some less important information - for at least me, don't know how other's think about it - of the DSL account information (user name and password) to personal informations stored with the 'astaro user interface'. The latter one is in my point of view critical: No one, neither domain admin, firewall admin or whatever, should/must know personal credentials of other users! Even worse, the file itself has access mode 644, so a login user without root/admin-permissions can get the informations.

Just think about the fact an external service supplier can get very sensitive information no one would hand him out voluntarily!

Dear astaro developers, you should really pay a little more attention to your debug code. A firewall system is a high security system which should not store sensitive data in plaine text - in case of a successfully intrusion there might be pretty valuable information available.

You should really fix all that password weaknesses as soon as possible - at least it should been solved with the GA of Astaro 7.2

With reagards

Wolperdinger
  #2 (permalink)  
Old 05-21-2008, 10:12 PM
bitonw's Avatar
Senior Member
 
Join Date: Jun 2004
Location: UK, Europe
Posts: 156
Default

is it possible that in the 'beta' test versions those files are logging this kind of info for debug purposes?
__________________
asl latest version jetway J7F2WE2G / 1024mb / sata 120gb / AD3RTLANP / cubid 3688

bit4net
bt
  #3 (permalink)  
Old 05-23-2008, 08:26 AM
tom's Avatar
tom tom is offline
Super Moderator
 
Join Date: Nov 2000
Location: Heidelberg, Germany
Posts: 1,231
Default

The emailpki-debug.log will be gone in 7.300.

We try to avoid storing un-hashed passwords. Sometimes this is not possible for technical reasons. We'll check if we can tighten permissons on the mentioned file.
__________________
Tom Kistner
Product Development & Administrator
Astaro AG
 

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 12:56 AM.

 

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.


These pages are specifically maintained for the discussion of firewall issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases. issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases.