From: SourceForge.net <no...@so...> - 2007-05-12 19:08:36
|
Bugs item #1717620, was opened at 2007-05-12 04:33 Message generated for change (Comment added) made by globalqss You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=879332&aid=1717620&group_id=176962 Please note that this message will contain a full copy of the comment thread, including the initial issue submission, for this request, not just the latest update. Category: Security Group: v3.2.0 Status: Open Resolution: None >Priority: 9 Private: No Submitted By: Timo Kontro (kontro) Assigned to: Nobody/Anonymous (nobody) Summary: DB password printed on screen. Initial Comment: Starting client using following line: java -cp AdempiereCLib.jar:Adempiere.jar org.compiere.db.CConnection Prints out: Connection = CConnection[name=MyAppsServer{MyDBServer-MyDBName-adempiere},AppsHost=MyAppsServer,AppsPort=1099,Profile=L,type=,DBhost=MyDBServer,DBport=0,DBname=MyDBName,BQ=false,FW=false,FWhost=,FWport=0,UID=adempiere,PWD=adempiere] >> CConnection[name=MyAppsServer{MyDBServer-MyDBName-adempiere},AppsHost=MyAppsServer,AppsPort=1099,Profile=L,type=,DBhost=MyDBServer,DBport=0,DBname=MyDBName,BQ=false,FW=false,FWhost=,FWport=0,UID=adempiere,PWD=adempiere] ---------------------------------------------------------------------- >Comment By: Carlos Ruiz (globalqss) Date: 2007-05-12 14:08 Message: Logged In: YES user_id=1180760 Originator: NO Hi Kontro, thanks for reporting. I'm raising priority to 9, all security issues without workaround are criticial IMHO. So, if someone found a workaround we can document it and low the priority to 7. Any suggestion? 1 - I think the main method is not needed in CConnection (it can be deleted). 2 - I think the best option is to implement the WAN connection without saving password in preference file (not sure if it works currently) Regards, Carlos Ruiz ---------------------------------------------------------------------- You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=879332&aid=1717620&group_id=176962 |