Hi Davide,

Davide Libenzi wrote:

>On Tue, 23 Sep 2003, . wrote:
>
>  
>
>>I have enabled POP logs. Is there any way to hide passwords in that log?
>>    
>>
>
>What about setting the correct permissions to MAIL_ROOT ?
>  
>

I agree with Vitor and Michal. IMHO storing unencrypted passwords 
anywhere is a bad idea, and to log username/password pairs in a log file 
is a crackers dream. If your mail server is compromised, it's already 
too late for that system. But that doesn't make it ok to expose 
passwords that could compromise the entire network.

Users, myself included :-(  often reuse passwords for multiple different 
logins. While this is not recommended it is very common. Those logged 
passwords most likely also access many other user accounts in your 
network and other networks.

Why would an administrator need to know the password used for a 
successful login in the first place? I would prefer to see that field 
removed from the log altogether.

Jeff



-
To unsubscribe from this list: send the line "unsubscribe xmail" in
the body of a message to [EMAIL PROTECTED]
For general help: send the line "help" in the body of a message to
[EMAIL PROTECTED]

Reply via email to