I'm not sure if this is the appropriate place to be posting this, so if not, 
please feel free to move it to the relevant forum.  This is from one of the 
community zenpacks, but I seem to recall the issue of passwords in clear text 
in the event log was a problem for other things too.

When viewing an event (warning - yellow) of class Perf/Memory "Command timed 
out on device DEVICENAME", the password is shown in clear text.


Code:
        Command timed out on device DEVICENAME: 
$ZENHOME/Products/WindowsWMIDeviceTemplateV2/libexec/check_wmic_disk.pl 
"192.168.1.101" "Domain/Username" "password"



Given that it is just recording the command line parameters sent, I'm not sure 
exactly how this can be addressed, but it is a concern given the privileges 
required for WMI interaction.  I'd guess some generic way of hiding passwords 
from various logs is needed.




-------------------- m2f --------------------

Read this topic online here:
http://community.zenoss.com/forums/viewtopic.php?p=15421#15421

-------------------- m2f --------------------



_______________________________________________
zenoss-users mailing list
[email protected]
http://lists.zenoss.org/mailman/listinfo/zenoss-users

Reply via email to