Hello all,

While trouble shooting an ftp problem today I came across something scary. The file /var/log/auth.log has newly added ftp account info in it, INCLUDING PASSWORD! Now I know only root can read this, but pending someone has become root, they now have passwords for all ftp accounts. This is not good.

Thought I might bring this to attention.


Steve