[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#253700: konqueror history exposure of username and password



This one time, at band camp, Jean Darcoux said:
> Package: konqueror
> Version: 4:3.2.2-1
> Severity: important
> Tags: security sarge
> 
> If you enter an URL like
> 
> ftp://USER:PASS@ftp.site.com
> 
> in the URL bar and type enter. The next time you will type the same URL, 
> you will see that the username and the password will be autocompleted. This 
> indicate that they are stored somewhere on your computer. This can be a 
> security problem in the case of a shared computer.

You understand that linux is a _multi-user_ OS.  So, setup seperate user
accounts, so that each person can have each of their settings and
history kept private.  This information is most likely stored in the
users ~/.kde/, which is not world-readable here.

HTH, and thanks,
-- 
 -----------------------------------------------------------------
|   ,''`.					     Stephen Gran |
|  : :' :					 sgran@debian.org |
|  `. `'			Debian user, admin, and developer |
|    `-					    http://www.debian.org |
 -----------------------------------------------------------------

Attachment: pgpwuxrHd2gia.pgp
Description: PGP signature


Reply to: