Bugtraq mailing list archives

cleartext passwords in Remedy processes' cores


From: grina () grina com (Peter A. Grina)
Date: Wed, 13 Nov 1996 14:04:20 -0500


Remedy makes an elaborate and very popular trouble ticket program that has
been installed in lots of sites (Wall Street firms included.)

The security hole in Remedy's product is that a core dump of either the user
processes (i.e. aruser, notifier) shows the user's password in clear text.

The other security hole exists on the Remedy server... core dumps of either
of these two daemons:

                                arserverd
                                ntserverd
... reveals the same things.  The nsserverd core dump is especially nasty
since it puts the username and (cleartext) password on the same line.

-Pete Grina (grina () grina com)

p.s.  This was called in to Remedy.



Current thread: