Results 1 to 3 of 3

Thread: Cleartext password in log file

  1. #1
    Join Date
    Oct 2008
    Posts
    2
    Rep Power
    7

    Default Cleartext password in log file

    I was looking at my zimbra log file trying to determine why my zdesktop on 64-bit vista was hanging on the "loading" screen (turns out it was a huge sync), when I see my username and password to my zimbra account just sitting there between two <debug> tags in the log file. This is ridiculous. Sure its a beta, but lets refrain from writing cleartext passwords to a log file.

    I have since moved to 64-bit Ubuntu, but there is no native 64-bit linux zdesktop. Since most power users are migrating to 64 bit linux, it would be great to have zdesktop on that platform without hacking to run a 32-bit version.

  2. #2
    Join Date
    Oct 2005
    Location
    Thatcher, AZ
    Posts
    5,606
    Rep Power
    21

    Default

    What version? This was fixed in Beta 2 or 3. We're now at 4.

  3. #3
    Join Date
    Oct 2008
    Posts
    2
    Rep Power
    7

    Default

    I am running 0.91 build 1344, fresh off the website.

    The offending debug statement was in my zdesktop.log file and it had this format:

    2008-10-18 21:04:27,961 DEBUG [btpool0-8] [name=zimbra;ip=127.0.0.1;] request - <AuthRequest xmlns="urn:zimbraAccount"><account by="name">MYACCOUNT@MYHOST.COM</account><password>MYPLAINTEXTPASSWORD</password></AuthRequest>

    I don't think that it is transmitting my password in cleartext to the zimbra server as I checked "use SSL" (which I don't know why that's not the default); this was stored in a local zimbra log file.
    Last edited by d_war; 10-22-2008 at 02:19 PM.

Similar Threads

  1. speed up the net
    By mcesari in forum Administrators
    Replies: 10
    Last Post: 04-25-2008, 12:24 PM
  2. Error Installing Outlook Connector
    By DanO in forum Zimbra Connector for Outlook
    Replies: 17
    Last Post: 08-28-2007, 10:35 AM
  3. centos 5 zimbra 4.5.6 no statistics
    By rutman286 in forum Installation
    Replies: 9
    Last Post: 08-14-2007, 10:30 AM
  4. Traslation SVN tree status
    By meikka in forum I18N/L10N - Translations
    Replies: 7
    Last Post: 02-13-2007, 11:13 AM
  5. M3 problem with shares
    By titangears in forum Users
    Replies: 4
    Last Post: 01-12-2006, 01:01 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •