[13947] in bugtraq
Sun Internet Mail Server
daemon@ATHENA.MIT.EDU (Michal Krzysztofowicz)
Mon Feb 21 16:34:57 2000
Mime-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Message-Id: <Pine.SOL.4.21.0002200031320.22675-100000@klayman.hq.formus.pl>
Date: Sun, 20 Feb 2000 00:36:57 +0100
Reply-To: Michal Krzysztofowicz <mike@ISP.FORMUS.PL>
From: Michal Krzysztofowicz <mike@ISP.FORMUS.PL>
X-To: BUGTRAQ@SECURITYFOCUS.COM
To: BUGTRAQ@SECURITYFOCUS.COM
Hello,
Sorry if this subject was discussed before..
I have just discovered, that during the install process, SIMS creates a
world-readable /tmp/sims_setup.dat file, which, among the others, contains
all the passwords in clear text.
Here's the example:
administrator-name=Directory Manager
administrator-passwd=dupa.8
administrator-passwd2=dupa.8
siteadmin-name=siteadmin
siteadmin-passwd=dupa.8
siteadmin-passwd2=dupa.8
No comments...
Best Regards,
Michal Krzysztofowicz
UNIX Systems Administrator
Formus Polska Sp. z o.o.