Kayako logo
SupportSuite, eSupport and LiveResponse Discussion, troubleshooting and feedback related to Kayako's flagship support desk products SupportSuite, eSupport and LiveResponse.

Closed Thread
 
LinkBack Thread Tools Search this Thread Display Modes
  (#1) Old
netaddict Offline
Member
 
Posts: 95
Join Date: Mar 2008
Location: Adelaide, Australia
Clear text passwords publicly visible? - 26-10-2008, 01:34 AM

I've just been doing some setting up of SupportSuite, finally, and noticed something that concerns me.

I have to run http://www.domain.com/helpdesk/cron/index.php?_t=parser to try to work out why emails weren't being fetched.

In doing that I noticed that the password for the pop3 box is showin in clear text as output. To me this is a security risk. Anyone who knows you are running Kayako can try this command and see the passwords to your pop3 box's (assuming your using pop3 and not pipe)

Example is shown below, passwords and domain blacked out.


I did have a issue where Kayako Support gave me a new cron_parser.php to use as I was getting the below error:
Thu Oct 16 04:05:02 2008] [error] [client 208.43.x.x] PHP Warning: file_exists() [function.file-exists]: open_basedir restriction in effect. File(./files/parser.lockfile) is not within the allowed path(s): (/var/www/vhosts/domain.net/httpdocs:/tmp) in /var/www/vhosts/domain.net/httpdocs/helpdesk/modules/parser/cron_parser.php on line 32

Since getting the update that error no longer occurs.

I've never noticed the plain text passwords before, have I configured something wrong or is this a issue with Kayako? If it is I'd say its a rather large one as it exposes what I'd call a security risk.

I'm also logging a support ticket about this however its atleast 24+ hours before support are open.

Thanks,
Dylan

Last edited by netaddict; 26-10-2008 at 01:35 AM.. Reason: added note re support
   
  (#2) Old
craigbrass Offline
Senior Member
 
Posts: 5,922
Join Date: Jun 2005
Location: Cumbria, UK
26-10-2008, 10:09 AM

Wow, thats bad. Are you running the latest version? If so, this needs developer attention ASAP.

Piping, as described in the manual, is one option for you.

Also, out of interest, why have you blanked your email address out?


Craig Brass - Kayako Forum Squatter (Note: I am NOT a staff member)

Icon Headquarters - Its Elixir - Web2Messenger

Last edited by craigbrass; 26-10-2008 at 10:10 AM..
   
  (#3) Old
netaddict Offline
Member
 
Posts: 95
Join Date: Mar 2008
Location: Adelaide, Australia
26-10-2008, 10:17 AM

Running version 3.30.02 SupportSuite Stable.

I'd personally rather not use piping, rather have it come from POP3, more safer in my view in the event of any failure.

Blocked out the email address's for my protection, happy to provide the domain name etc via PM to any staff member. Also most would be able to see who I am from my email address and look up the ticket.
   
  (#4) Old
Jamie Edwards Offline
Operations Manager
 
Jamie Edwards's Avatar
 
Posts: 5,664
Join Date: Jan 2006
Location: United Kingdom
26-10-2008, 10:34 AM

Hi netaddict,

Please upload the attached file, replacing yours in (modules\parser\cron_parser.php).

I understand that our support staff updated cron_parser.php for you? Please let me know the related ticket ID so I can take a look.
Attached Files
File Type: php cron_parser.php (8.1 KB, 2 views)


Jamie Edwards (jamie.edwards ]at[ kayako.com)
----------------------------------------------------------------
---
   
  (#5) Old
netaddict Offline
Member
 
Posts: 95
Join Date: Mar 2008
Location: Adelaide, Australia
26-10-2008, 10:48 AM

Updated the cron_parser.php file as you posted and it changed the output, no passwords

However now the error_log file is generating errors again as in the original post prior to updating it as supplied from support.

I've also PM'd you the ticket ID.

Thanks,
Dylan

Last edited by netaddict; 26-10-2008 at 10:49 AM.. Reason: clarify
   
  (#6) Old
Jamie Edwards Offline
Operations Manager
 
Jamie Edwards's Avatar
 
Posts: 5,664
Join Date: Jan 2006
Location: United Kingdom
26-10-2008, 10:58 AM

Hi Dylan,

Please see the attached file which should resolve this.

I am very sorry on behalf of our support technicians that you were given this debug file as a production file. I have contacted the people concerned, and make absolutely certain this isn't going to happen again.
Attached Files
File Type: php cron_parser.php (8.0 KB, 3 views)


Jamie Edwards (jamie.edwards ]at[ kayako.com)
----------------------------------------------------------------
---
   
  (#7) Old
netaddict Offline
Member
 
Posts: 95
Join Date: Mar 2008
Location: Adelaide, Australia
26-10-2008, 11:05 AM

Thanks Jamie, looks to have fixed the issue.

I've added a referance to the ticket so support can close it.
   
  (#8) Old
craigbrass Offline
Senior Member
 
Posts: 5,922
Join Date: Jun 2005
Location: Cumbria, UK
26-10-2008, 11:28 AM

Quote:
I've also PM'd you the ticket ID.
Ticket IDs are find to post here on the forum directly.


Craig Brass - Kayako Forum Squatter (Note: I am NOT a staff member)

Icon Headquarters - Its Elixir - Web2Messenger
   
  (#9) Old
Jamie Edwards Offline
Operations Manager
 
Jamie Edwards's Avatar
 
Posts: 5,664
Join Date: Jan 2006
Location: United Kingdom
26-10-2008, 11:32 AM

Quote:
Originally Posted by craigbrass View Post
Ticket IDs are find to post here on the forum directly.
And they are fine in a PM to Kayako staff as well


Jamie Edwards (jamie.edwards ]at[ kayako.com)
----------------------------------------------------------------
---
   
  (#10) Old
craigbrass Offline
Senior Member
 
Posts: 5,922
Join Date: Jun 2005
Location: Cumbria, UK
26-10-2008, 11:40 AM

Indeed, but with what I suggested being quicker to do. Just making observations.


Craig Brass - Kayako Forum Squatter (Note: I am NOT a staff member)

Icon Headquarters - Its Elixir - Web2Messenger
   
  (#11) Old
bear Offline
Community Moderator
 
Posts: 674
Join Date: Jan 2005
26-10-2008, 01:33 PM

Quote:
Originally Posted by craigbrass View Post
Indeed, but with what I suggested being quicker to do. Just making observations.
Takes the same amount of time to PM as to post, so it makes little difference.
   
Closed Thread

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
eSupport stores user passwords as plain text MarcG SupportSuite, eSupport and LiveResponse 1 17-10-2008 09:59 PM
"<<<<" breaks visible text bear SupportSuite, eSupport and LiveResponse 3 20-02-2008 08:14 PM
Misc / General System -> Password encryption or hashing NC Software Will Implement (V4) 46 16-02-2008 01:12 AM



Powered by vBulletin® Version 3.7.5
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.2.0
Help desk software by Kayako.


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48