Welcome, Guest
Please Login or Register.
Lost Password?
Re:$HOME/.usermin/inbox.imap - Why the plaintext P (1 viewing)
Post Reply

TOPIC: Re:$HOME/.usermin/inbox.imap - Why the plaintext P

#14536
maxslug (User)
Posts: 25
graphgraph
$HOME/.usermin/inbox.imap - Why the plaintext PW? 2008/07/07 12:34  
I just stumbled onto the file $HOME/.usermin/inbox.imap, and inside it has the plaintext copy of the password for that account. On both the main user and the sub accounts.

What is this file used for, and can it be safely removed? I'm really not a fan of having plaintext passwords laying around for every account on my box.

Thanks in advance,
-m
  The administrator has disabled public write access.
#14537
ronald (User)
Posts: 511
graphgraph
Re:$HOME/.usermin/inbox.imap - Why the plaintext P 2008/07/07 13:33  
i suppose it is for the email client (such as thunderbird or outlook express) to authenticate when logging in for checking for any new mails.
The password for awstats is also plaintext.

in dovecots module config you can also use other ways however you need to do some configuration and Im not too familiar with this.

No one but the owner should be able to open that file IF your server is reasonably protected (which it is not by default and never assume it is)

Post edited by: ronald, at: 2008/07/07 14:01
  The administrator has disabled public write access.
#14589
maxslug (User)
Posts: 25
graphgraph
Re:$HOME/.usermin/inbox.imap - Why the plaintext P 2008/07/08 13:32  
these days it's getting harder and harder to keep a file system protected completely. Now my box is actually a xen instance -- who knows who can mount my partition w/out me knowing or any number of security compromises.

I'm just hoping that all services can authenticate against PAM or /etc/shadow and that there is no need for plaintext laying around, but maybe that's a lot to ask for.

-m
  The administrator has disabled public write access.
#14591
ronald (User)
Posts: 511
graphgraph
Re:$HOME/.usermin/inbox.imap - Why the plaintext P 2008/07/08 16:54  
in the users and groups module is an option to conceal plain passwords. perhaps that helps, i do not know
also you can have dovecot use md5/encrypted passwords (for the imap)
  The administrator has disabled public write access.
#14625
maxslug (User)
Posts: 25
graphgraph
Re:$HOME/.usermin/inbox.imap - Why the plaintext P 2008/07/09 08:27  
Thanks for the ideas.

Looks like the option is to just hide the passwords in the web front-end,
and the imap option is for authentication methods, not for local storage.

dovecot is already configured to use PAM, so it does not need to store any passwords, just ask for credentials from PAM.

So i'm still left wondering what process is using this plain-text password file?
  The administrator has disabled public write access.
Post Reply
get the latest posts directly to your desktop

Talk and Get Help

Support
Forums
Bugs and Issues

Get Virtualmin

OS Support
Buy Online
Download
Copyright 2005-2007 Virtualmin, Inc. All rights reserved.