Hello all,
While trouble shooting an ftp problem today I came across something scary. The file /var/log/auth.log has newly added ftp account info in it, INCLUDING PASSWORD! Now I know only root can read this, but pending someone has become root, they now have passwords for all ftp accounts. This is not good.
Thought I might bring this to attention.
Steve



LinkBack URL
About LinkBacks
Reply With Quote




