Hi Davide, Davide Libenzi wrote:
>On Tue, 23 Sep 2003, . wrote: > > > >>I have enabled POP logs. Is there any way to hide passwords in that log? >> >> > >What about setting the correct permissions to MAIL_ROOT ? > > I agree with Vitor and Michal. IMHO storing unencrypted passwords anywhere is a bad idea, and to log username/password pairs in a log file is a crackers dream. If your mail server is compromised, it's already too late for that system. But that doesn't make it ok to expose passwords that could compromise the entire network. Users, myself included :-( often reuse passwords for multiple different logins. While this is not recommended it is very common. Those logged passwords most likely also access many other user accounts in your network and other networks. Why would an administrator need to know the password used for a successful login in the first place? I would prefer to see that field removed from the log altogether. Jeff - To unsubscribe from this list: send the line "unsubscribe xmail" in the body of a message to [EMAIL PROTECTED] For general help: send the line "help" in the body of a message to [EMAIL PROTECTED]
