as the input log is practically reading the keyboard, any password typed
during a sudosh session is stored in the input trace. Ok, the files are
only readable by root, but still I don't feel confident to have cleartext
passwords anywhere on the system.
As a workaround I currently disabled all input logging.
My idea would be: as soon as the tty is in non-echo mode don't log any
keystrokes. Is this possible?
Nobody/Anonymous
None
None
Public
|
Date: 2008-04-29 12:22
|
| Field | Old Value | Date | By |
|---|---|---|---|
| priority | 5 | 2008-04-14 12:26 | gunstick |
Copyright © 2009 Geeknet, Inc. All rights reserved. Terms of Use