Sun Internet Mail Server

From: Michal Krzysztofowicz (mikeat_private)
Date: Sat Feb 19 2000 - 15:36:57 PST

  • Next message: Kris Kennaway: "FreeBSD Security Advisory: FreeBSD-SA-00:03.asmon"

    Hello,
    
    Sorry if this subject was discussed before..
    
    I have just discovered, that during the install process, SIMS creates a
    world-readable /tmp/sims_setup.dat file, which, among the others, contains
    all the passwords in clear text.
    
    Here's the example:
    
    administrator-name=Directory Manager
    administrator-passwd=dupa.8
    administrator-passwd2=dupa.8
    siteadmin-name=siteadmin
    siteadmin-passwd=dupa.8
    siteadmin-passwd2=dupa.8
    
    No comments...
    
    Best Regards,
    
    Michal Krzysztofowicz
    UNIX Systems Administrator
    Formus Polska Sp. z o.o.
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 15:36:16 PDT