The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

FTP password in /var/log/auth.log

Discussion in 'General Discussion' started by shulshof, Aug 16, 2005.

  1. shulshof

    shulshof Registered

    Joined:
    Jul 7, 2005
    Messages:
    4
    Likes Received:
    0
    Trophy Points:
    1
    Hello all,

    While trouble shooting an ftp problem today I came across something scary. The file /var/log/auth.log has newly added ftp account info in it, INCLUDING PASSWORD! Now I know only root can read this, but pending someone has become root, they now have passwords for all ftp accounts. This is not good.

    Thought I might bring this to attention.


    Steve
     
Loading...

Share This Page