<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Warning usernames and passwords stored in clear text of the apache logs when testing with ldap in Expedition Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/expedition-discussions/warning-usernames-and-passwords-stored-in-clear-text-of-the/m-p/231517#M519</link>
    <description>&lt;P&gt;Warning if you use the test button next to an ldap server the userid and password are stored in clear text in /var/log/apache2/access.log since they are passed in the URL.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Example:&lt;/P&gt;
&lt;P&gt;&amp;lt;IP&amp;gt;&amp;nbsp;- - [19/Sep/2018:14:28:22 -0500] "GET /bin/authentication/servers/loginServers.php?_dc=1537385302801&amp;amp;id=1&amp;amp;type=LDAP&amp;amp;action=test&amp;amp;admin_user=&lt;FONT color="#FF0000"&gt;&amp;lt;userid&amp;gt;&lt;/FONT&gt;&amp;amp;admin_&lt;BR /&gt;password=&lt;FONT color="#FF0000"&gt;&amp;lt;password&amp;gt;&lt;/FONT&gt;&amp;nbsp;HTTP/1.1" 200 749&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this is on version 1.0.105&lt;/P&gt;</description>
    <pubDate>Wed, 19 Sep 2018 19:43:54 GMT</pubDate>
    <dc:creator>psuJohn</dc:creator>
    <dc:date>2018-09-19T19:43:54Z</dc:date>
    <item>
      <title>Warning usernames and passwords stored in clear text of the apache logs when testing with ldap</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/warning-usernames-and-passwords-stored-in-clear-text-of-the/m-p/231517#M519</link>
      <description>&lt;P&gt;Warning if you use the test button next to an ldap server the userid and password are stored in clear text in /var/log/apache2/access.log since they are passed in the URL.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Example:&lt;/P&gt;
&lt;P&gt;&amp;lt;IP&amp;gt;&amp;nbsp;- - [19/Sep/2018:14:28:22 -0500] "GET /bin/authentication/servers/loginServers.php?_dc=1537385302801&amp;amp;id=1&amp;amp;type=LDAP&amp;amp;action=test&amp;amp;admin_user=&lt;FONT color="#FF0000"&gt;&amp;lt;userid&amp;gt;&lt;/FONT&gt;&amp;amp;admin_&lt;BR /&gt;password=&lt;FONT color="#FF0000"&gt;&amp;lt;password&amp;gt;&lt;/FONT&gt;&amp;nbsp;HTTP/1.1" 200 749&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this is on version 1.0.105&lt;/P&gt;</description>
      <pubDate>Wed, 19 Sep 2018 19:43:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/warning-usernames-and-passwords-stored-in-clear-text-of-the/m-p/231517#M519</guid>
      <dc:creator>psuJohn</dc:creator>
      <dc:date>2018-09-19T19:43:54Z</dc:date>
    </item>
    <item>
      <title>Re: Warning usernames and passwords stored in clear text of the apache logs when testing with ldap</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/warning-usernames-and-passwords-stored-in-clear-text-of-the/m-p/231605#M525</link>
      <description>&lt;P&gt;Hi, Good catch. We will move the request from GET to POST to avoid Apache logs stores the credentials.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;lt;Remember&amp;gt; you are the owner of your Expedition VM and no one else has access to it other than you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for let us know and help us to improve Expedition.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Sep 2018 10:24:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/warning-usernames-and-passwords-stored-in-clear-text-of-the/m-p/231605#M525</guid>
      <dc:creator>alestevez</dc:creator>
      <dc:date>2018-09-20T10:24:47Z</dc:date>
    </item>
    <item>
      <title>Re: Warning usernames and passwords stored in clear text of the apache logs when testing with ldap</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/warning-usernames-and-passwords-stored-in-clear-text-of-the/m-p/231618#M526</link>
      <description>&lt;P&gt;Not disagreeing it is my expedition server, but if you are doing log forwarding or at a minium whomever has access to the cli has access to the logs until it gets rotated out and deleted. ( I haven't checked the logrotate settings)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Might I also suggest when you change that auth test to a post you also purge the apache2 accept logs or at least the values in those logs?&lt;/P&gt;</description>
      <pubDate>Thu, 20 Sep 2018 13:13:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/warning-usernames-and-passwords-stored-in-clear-text-of-the/m-p/231618#M526</guid>
      <dc:creator>psuJohn</dc:creator>
      <dc:date>2018-09-20T13:13:12Z</dc:date>
    </item>
    <item>
      <title>Re: Warning usernames and passwords stored in clear text of the apache logs when testing with ldap</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/warning-usernames-and-passwords-stored-in-clear-text-of-the/m-p/231885#M539</link>
      <description>&lt;P&gt;When we move to post the values will not be stored in the logs anymore and by now how you are root you can just remove your logs from&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;sudo cd /var/log/apache2/
sudo rm -rf access.log*
sudo rm -rf error.log*&lt;/PRE&gt;
&lt;P&gt;That will remove all your current logs.&lt;/P&gt;</description>
      <pubDate>Sat, 22 Sep 2018 06:27:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/warning-usernames-and-passwords-stored-in-clear-text-of-the/m-p/231885#M539</guid>
      <dc:creator>alestevez</dc:creator>
      <dc:date>2018-09-22T06:27:04Z</dc:date>
    </item>
  </channel>
</rss>

