We've expanded our news coverage and improved our search! Visit
oreilly.com for the latest or search for all things across O'Reilly!
| Weblog: |
|
New (local) Mac OS X vulnerability : Passwords in Swap files
|
| Subject: |
|
Not a problem here |
| Date: |
|
2004-06-28 08:28:11 |
| From: |
|
puggsly
|
Response to: Of course...
|
|
My system has been up and running for weeks (I can't imagine that everything has not been swapped out at one time or another). And there are a couple of entries that show up but none has my password.
What was the source of UserName and password that you saw? Was it a logon to an AFP share? Some web site name/password? or your initial log on? I know there are times when servers will not accept encrypted passwords that OS X will send them in the clear? Maybe that is your case?
Give us more info, so we can figure out what, if anything, is vulnerable?
|