Uploaded image for project: 'Core ReactOS'
  1. Core ReactOS
  2. CORE-8019

Logs contains clear administrator password

    XMLWordPrintable

    Details

    • Type: Bug
    • Status: Resolved
    • Priority: Critical
    • Resolution: Fixed
    • Fix Version/s: 0.3.17
    • Component/s: NTCore, Setup
    • Labels:
      None
    • Environment:

      bootcd-62554-dbg.iso
      VirtualBox 4.36

      Description

      Looking at my install log, I see it contains my Administrator password:
      (dll/win32/syssetup/security.c:333) SYSSETUP: SetAdministratorPassword(bk5ua2)

      I edited it before posting this bug.
      Where there is bk5ua2 my typed administrator password was.

      I believe it is a serious security issue that logs that are likely to be attached to bug reports contain the administrator password.

        Attachments

          Activity

            People

            • Assignee:
              ekohl ekohl
              Reporter:
              paul Paul Dufresne
            • Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved: