Cacti remote password retrieval security flaw?

Post general support questions here that do not specifically fall into the Linux or Windows categories.

Moderators: Developers, Moderators

Post Reply
evilzardoz
Cacti User
Posts: 55
Joined: Sun Dec 04, 2005 10:59 pm

Cacti remote password retrieval security flaw?

Post by evilzardoz »

Hi,

During some penetration testing, it was foud that an installation of cacti was vulnerable to having the passwords retrieved of accounts on the server!

Is this a known problem with 0.8.7e?

Is there a way to enable a form of one-way encryption to ensure that we don't get passwords compromised by an (illegitimate) third party?

Thanks
Post Reply

Who is online

Users browsing this forum: No registered users and 2 guests