PDA

View Full Version : Huge security issue?



dragos240
July 19th, 2009, 01:44 PM
I was browsing the wiki page for toribash, and it's having a database issue. But one thing I noticed is it tells you the root password :o.

121630

PartisanEntity
July 19th, 2009, 01:47 PM
Um it doesn't tell you the root password. All it shows you is the database username.

koenn
July 19th, 2009, 01:51 PM
too verbose error feedback is a indeed a (small) security issue as it can reveal some of the inner workings of the application, which can be helpful to someone looking for an attack vector,
but where exactly do you see that root password ?

dragos240
July 19th, 2009, 01:53 PM
too verbose error feedback is a indeed a (small) security issue as it can reveal some of the inner workings of the application, which can be helpful to someone looking for an attack vector,
but where exactly do you see that root password ?

at the bottom.

Barrucadu
July 19th, 2009, 01:53 PM
Are you interpreting "YES" as the root password? :p

Swagman
July 19th, 2009, 02:01 PM
121630 ?


[edit]
Nope.. thats comment No.

dragos240
July 19th, 2009, 02:03 PM
Are you interpreting "YES" as the root password? :p

Maybe :-\"

Barrucadu
July 19th, 2009, 02:17 PM
Well, that just shows that a password is being used in the connection attempt (as opposed to "using password: NO" if someone forgot to include it).

bodhi.zazen
July 19th, 2009, 02:51 PM
FYI security issues are probably not best reported in the Cafe on these forums.

There is a security section here.

Better yet use Launchpad, there is an option to report a bug as a security risk.

As the question is asked and answered, and this is not the right place, thread closed.