Vulnerability Development mailing list archives

Re: Red Hat 6.2's ftp segmentation fault


From: sec () ORGONE NEGATION NET (Jason Storm)
Date: Sat, 24 Jun 2000 15:54:22 -0700


On Fri, 23 Jun 2000, Philip Rowlands wrote:

The issue here is that your actual, cleartext password need *never*
appear on any disk, anywhere at any time. If it's being stored or
transmitted, it should be hashed or encrypted.

just about any daemon/application i can think of posesses a cleartext
password at some point via read().   snarfing passwords from sshd via
strace is trivial, for example.

if the core file is world readable, thats the issue i would concentrate
on, not its contents.

-jason storm
negation industries


Current thread: