Security Basics mailing list archives

McAfee ePolicy Orchestrator Agent Commandline Install Password in Plain Text


From: "Jack Cullen" <jack_cullen () hotmail com>
Date: Wed, 17 Mar 2004 18:11:38 -0500

Hardly earthshaking but the McAfee ePolicy Orchestrator Agent install process leaves the account and password info in plain text in the install log file. When the agent is installed via the command line using:

framepkg.exe /install=agent /username=<username> /password=<password>

the info can be found at:

C:\Documents and Settings\<username>\Local Settings\Temp\NAILogs\FrmInst_servername.log

If logon credentials are embedded into the install executable via the Admin Console (and no command line parameters used) then the username and password show up in the same log file as above however the password is encrypted. I don't know how well it is encrypted but I'm confident someone can knock it off.

_________________________________________________________________
Get tax tips, tools and access to IRS forms – all in one place at MSN Money! http://moneycentral.msn.com/tax/home.asp


---------------------------------------------------------------------------
Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off any course! All of our class sizes are guaranteed to be 10 students or less to facilitate one-on-one interaction with one of our expert instructors. Attend a course taught by an expert instructor with years of in-the-field pen testing experience in our state of the art hacking lab. Master the skills of an Ethical Hacker to better assess the security of your organization. Visit us at: http://www.infosecinstitute.com/courses/ethical_hacking_training.html
----------------------------------------------------------------------------


Current thread: