Re: password leak in mylog thru win odbc

From: "Dave Page" <dpage(at)vale-housing(dot)co(dot)uk>
To: "pg" <pg(at)newhonest(dot)com>, <pgsql-odbc(at)postgresql(dot)org>
Subject: Re: password leak in mylog thru win odbc
Date: 2003-03-20 21:37:19
Message-ID: 03AF4E498C591348A42FC93DEA9661B8259E09@mail.vale-housing.co.uk
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-odbc

> -----Original Message-----
> From: pg [mailto:pg(at)newhonest(dot)com]
> Sent: 19 March 2003 06:22
> To: pgsql-odbc(at)postgresql(dot)org
> Subject: [ODBC] password leak in mylog thru win odbc
>
> But if a user enable the mylog in odbc, the password (pwd)
> shows up there in mylogxxxxx.
>
> What can I do to hide the password?

Hi Jason,

If you use MD5 password authentication, does it still save the password
in the log, or the MD5 hash? If the latter, is that secure enough for
you, or might your users make use of it?

Regards, Dave.

Responses

Browse pgsql-odbc by date

  From Date Subject
Next Message Giuliano Gavazzi 2003-03-21 00:27:57 Re: .ini parsing
Previous Message Chris Gamache 2003-03-20 21:32:49 Re: password leak in mylog thru win odbc