[13947] in bugtraq

home help back first fref pref prev next nref lref last post

Sun Internet Mail Server

daemon@ATHENA.MIT.EDU (Michal Krzysztofowicz)
Mon Feb 21 16:34:57 2000

Mime-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Message-Id:  <Pine.SOL.4.21.0002200031320.22675-100000@klayman.hq.formus.pl>
Date:         Sun, 20 Feb 2000 00:36:57 +0100
Reply-To: Michal Krzysztofowicz <mike@ISP.FORMUS.PL>
From: Michal Krzysztofowicz <mike@ISP.FORMUS.PL>
X-To:         BUGTRAQ@SECURITYFOCUS.COM
To: BUGTRAQ@SECURITYFOCUS.COM

Hello,

Sorry if this subject was discussed before..

I have just discovered, that during the install process, SIMS creates a
world-readable /tmp/sims_setup.dat file, which, among the others, contains
all the passwords in clear text.

Here's the example:

administrator-name=Directory Manager
administrator-passwd=dupa.8
administrator-passwd2=dupa.8
siteadmin-name=siteadmin
siteadmin-passwd=dupa.8
siteadmin-passwd2=dupa.8

No comments...

Best Regards,

Michal Krzysztofowicz
UNIX Systems Administrator
Formus Polska Sp. z o.o.

home help back first fref pref prev next nref lref last post