OSSEC 2.8 umask Clear Text Passwords

2014.09.17
Credit: aramosf
Risk: Medium
Local: No
Remote: Yes
CVE: N/A
CWE: N/A

OSSEC 2.8 umask problem with clear text passwords :-( # aramosf@unsec.net / SecurityByDefault.com root@digitalsec:/home/aramosf# /var/ossec/agentless/register_host.sh add ossec@server1 Please provide password for host ossec@server1. Password: Please provide additional password for host ossec@server1 (<enter> for empty). Password: *Host ossec@server1 added. root@digitalsec:/home/aramosf# cat /var/ossec/agentless/.passlist ossec@server1|test|test2 root@digitalsec:/home/aramosf# ls -la /var/ossec/agentless/.passlist -rwxr--r-- 1 root root 83 Sep 15 14:35 /var/ossec/agentless/.passlist root@digitalsec:/home/aramosf#


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top