syslog security issue
- This topic has 0 replies, 1 voice, and was last updated 9 years ago by .
Viewing 1 post (of 1 total)
Viewing 1 post (of 1 total)
- You must be logged in to reply to this topic.
Tagged: isms syslog
Hello,
I wanted to let you know that the syslog functionality has some serious flaws. Most of the logs do not contain any useful info, there is no way to specify what level of logs to send.
And the biggest flaw of all => When a user logs in, the password is sent in cleartext to the syslog server.
All of the above makes this functionality completely unusable. Please consider fixing at least the clear-text password.
Grtz
Willem