Please whitelist cPanel in your adblocker so that you’re able to see our version release promotions, thanks!

The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

FTP password in /var/log/auth.log

Discussion in 'General Discussion' started by shulshof, Aug 16, 2005.

  1. shulshof

    shulshof Registered

    Jul 7, 2005
    Likes Received:
    Trophy Points:
    Hello all,

    While trouble shooting an ftp problem today I came across something scary. The file /var/log/auth.log has newly added ftp account info in it, INCLUDING PASSWORD! Now I know only root can read this, but pending someone has become root, they now have passwords for all ftp accounts. This is not good.

    Thought I might bring this to attention.


Share This Page