<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
	<channel>
		<title><![CDATA[Latest posts for the topic "Major security hole - Domain Administrator Password"]]></title>
		<link>http://www.sysaid.com/Sysforums/posts/list/57.page</link>
		<description><![CDATA[Latest messages posted in the topic "Major security hole - Domain Administrator Password"]]></description>
		<generator>JForum - http://www.jforum.net</generator>
			<item>
				<title>Major security hole - Domain Administrator Password</title>
				<description><![CDATA[ Is everyone aware that there domain password is sitting in plain text within an XML file on there server??<br /> <br /> Thought you might like to know that your system is not as secure as one might like.<br /> <br /> This is especially the case if your machine is accessible from the internet (DMZ)]]></description>
				<guid isPermaLink="true">http://www.sysaid.com/Sysforums/posts/preList/3959/18253.page</guid>
				<link>http://www.sysaid.com/Sysforums/posts/preList/3959/18253.page</link>
				<pubDate><![CDATA[Thu, 18 Mar 2010 16:46:33]]> GMT</pubDate>
				<author><![CDATA[ UserInterface]]></author>
			</item>
			<item>
				<title>Major security hole - Domain Administrator Password</title>
				<description><![CDATA[ Are you talking in regards to AD integration?<br /> <br /> If so, best practice is to use a service account with limited rights and not a domain admin account for this connection.]]></description>
				<guid isPermaLink="true">http://www.sysaid.com/Sysforums/posts/preList/3959/18254.page</guid>
				<link>http://www.sysaid.com/Sysforums/posts/preList/3959/18254.page</link>
				<pubDate><![CDATA[Thu, 18 Mar 2010 17:07:40]]> GMT</pubDate>
				<author><![CDATA[ Brian Martin]]></author>
			</item>
			<item>
				<title>Re:Major security hole - Domain Administrator Password</title>
				<description><![CDATA[ I'm just venturing a guess here but...<br /> <br /> Did you enter your domain administrator credentials in SysAid for something such as LDAP integration?<br /> <br /> This is why you create a user account with only the permissions required to make LDAP queries (read-only) and use that account in SysAid and not your domain Admin account.<br /> <br /> I rarely, and I mean rarely, use my domain admin account for anything.  Promoting Domain Controllers, Changing FSMO roles, etc.<br /> <br /> Using it to grant software access to our AD is against our security policy.<br /> <br /> Again, just a guess here.]]></description>
				<guid isPermaLink="true">http://www.sysaid.com/Sysforums/posts/preList/3959/18255.page</guid>
				<link>http://www.sysaid.com/Sysforums/posts/preList/3959/18255.page</link>
				<pubDate><![CDATA[Thu, 18 Mar 2010 17:10:47]]> GMT</pubDate>
				<author><![CDATA[ Scott the Admin]]></author>
			</item>
			<item>
				<title>Re:Major security hole - Domain Administrator Password</title>
				<description><![CDATA[ Sorry should have said that I have resolved our problem with this but wanted to make sure that others knew that this was the case... I only discovered it because a support person opened it up in front of me..<br /> That meant that I had to change our domain admin password again..<br /> <br /> If you don't know the password is there you would assume that it would be encrypted as it is a simple thing to do and most products of this size would have this enabled by default..]]></description>
				<guid isPermaLink="true">http://www.sysaid.com/Sysforums/posts/preList/3959/18259.page</guid>
				<link>http://www.sysaid.com/Sysforums/posts/preList/3959/18259.page</link>
				<pubDate><![CDATA[Thu, 18 Mar 2010 18:16:20]]> GMT</pubDate>
				<author><![CDATA[ UserInterface]]></author>
			</item>
			<item>
				<title>Major security hole - Domain Administrator Password</title>
				<description><![CDATA[ Any passwords regardless of the role no matter how limited they are, should NOT be on plain sight for unauthorized users to view.<br /> ]]></description>
				<guid isPermaLink="true">http://www.sysaid.com/Sysforums/posts/preList/3959/18268.page</guid>
				<link>http://www.sysaid.com/Sysforums/posts/preList/3959/18268.page</link>
				<pubDate><![CDATA[Fri, 19 Mar 2010 03:04:32]]> GMT</pubDate>
				<author><![CDATA[ Obelix]]></author>
			</item>
			<item>
				<title>Re:Major security hole - Domain Administrator Password</title>
				<description><![CDATA[ We use a service account, but I am still curious which XML file.<br /> <br /> I am also curious if this will be corrected.<br /> <br /> -Evan]]></description>
				<guid isPermaLink="true">http://www.sysaid.com/Sysforums/posts/preList/3959/18280.page</guid>
				<link>http://www.sysaid.com/Sysforums/posts/preList/3959/18280.page</link>
				<pubDate><![CDATA[Fri, 19 Mar 2010 10:20:20]]> GMT</pubDate>
				<author><![CDATA[ Evan]]></author>
			</item>
			<item>
				<title>Re:Major security hole - Domain Administrator Password</title>
				<description><![CDATA[ Hi all,<br /> <br /> Sorry for the misunderstanding...<br /> <br /> We usually suggest to use a user with read only right for the LDAP integration.<br /> <br /> @ Evan @  I think that this is not the place for questions like that for everyone to see the answer.]]></description>
				<guid isPermaLink="true">http://www.sysaid.com/Sysforums/posts/preList/3959/18283.page</guid>
				<link>http://www.sysaid.com/Sysforums/posts/preList/3959/18283.page</link>
				<pubDate><![CDATA[Fri, 19 Mar 2010 12:13:46]]> GMT</pubDate>
				<author><![CDATA[ itayH]]></author>
			</item>
			<item>
				<title>Re:Major security hole - Domain Administrator Password</title>
				<description><![CDATA[ I think that this is exactly the place to discuss such.. how else do we make sure that this gets fixed asap..]]></description>
				<guid isPermaLink="true">http://www.sysaid.com/Sysforums/posts/preList/3959/18304.page</guid>
				<link>http://www.sysaid.com/Sysforums/posts/preList/3959/18304.page</link>
				<pubDate><![CDATA[Fri, 19 Mar 2010 22:20:15]]> GMT</pubDate>
				<author><![CDATA[ UserInterface]]></author>
			</item>
			<item>
				<title>Re:Major security hole - Domain Administrator Password</title>
				<description><![CDATA[ It's probably not the best way to handle a security threat by telling everyone how to hack your system. But that just me thinking.<br /> <br /> You contact us for more info.]]></description>
				<guid isPermaLink="true">http://www.sysaid.com/Sysforums/posts/preList/3959/18314.page</guid>
				<link>http://www.sysaid.com/Sysforums/posts/preList/3959/18314.page</link>
				<pubDate><![CDATA[Sun, 21 Mar 2010 05:44:15]]> GMT</pubDate>
				<author><![CDATA[ itayH]]></author>
			</item>
			<item>
				<title>Re:Major security hole - Domain Administrator Password</title>
				<description><![CDATA[ Hi All,<br /> <br /> Just a clarification:<br /> <br /> The LDAP password that appears in the XML file is encrypted and has been this way since it has been fixed in release 5.6.<br /> <br /> UserInterface , I suggest you contact our support with more details, so what you see can be further investigated<br /> <br /> Oded<br /> <br /> <br /> <br /> ]]></description>
				<guid isPermaLink="true">http://www.sysaid.com/Sysforums/posts/preList/3959/18318.page</guid>
				<link>http://www.sysaid.com/Sysforums/posts/preList/3959/18318.page</link>
				<pubDate><![CDATA[Sun, 21 Mar 2010 06:14:13]]> GMT</pubDate>
				<author><![CDATA[ Oded  M]]></author>
			</item>
			<item>
				<title>Re:Major security hole - Domain Administrator Password</title>
				<description><![CDATA[ [quote=Oded  M]Hi All,<br /> <br /> Just a clarification:<br /> <br /> The LDAP password that appears in the XML file is encrypted and has been this way since it has been fixed in release 5.6.<br /> <br /> UserInterface , I suggest you contact our support with more details, so what you see can be further investigated<br /> <br /> Oded<br /> <br /> <br /> <br /> [/quote]<br /> <br /> I have 6.5.08, and am telling you that it is not encrypted in side that file. It is in plain text.]]></description>
				<guid isPermaLink="true">http://www.sysaid.com/Sysforums/posts/preList/3959/18334.page</guid>
				<link>http://www.sysaid.com/Sysforums/posts/preList/3959/18334.page</link>
				<pubDate><![CDATA[Sun, 21 Mar 2010 18:26:01]]> GMT</pubDate>
				<author><![CDATA[ UserInterface]]></author>
			</item>
			<item>
				<title>Re:Major security hole - Domain Administrator Password</title>
				<description><![CDATA[ [quote=itayH]It's probably not the best way to handle a security threat by telling everyone how to hack your system. But that just me thinking.<br /> <br /> You contact us for more info.[/quote]<br /> <br /> I contacted you and you told me that it is not a threat due to these reasons<br /> <br /> A. You have to have access to the server machine itself in order to view the file, usually, if you have that ability, you are probably an Administrator on that system and therefore should be able to see the DB password if needed.<br /> <br /> B. If you managed to get access to the server by some unthinkable way, you are still probably not a SysAid user and will not know where to look for such information and the probability is that even if you see the ServerConf file you will not know what you are looking at<br /> <br /> This not the response that should have been given to me. I think that everyone here will agree to what you say but it is a moot point. The point is that if someone gains access to any of our servers through any means, I do not want any passwords in plain text on my system.. This is why I would like a patch for this asap..]]></description>
				<guid isPermaLink="true">http://www.sysaid.com/Sysforums/posts/preList/3959/18335.page</guid>
				<link>http://www.sysaid.com/Sysforums/posts/preList/3959/18335.page</link>
				<pubDate><![CDATA[Sun, 21 Mar 2010 18:30:47]]> GMT</pubDate>
				<author><![CDATA[ UserInterface]]></author>
			</item>
			<item>
				<title>Re:Major security hole - Domain Administrator Password</title>
				<description><![CDATA[ I agree. please make this a feature request. No plain text passwords stored on sysaid servers or clients. <br /> ]]></description>
				<guid isPermaLink="true">http://www.sysaid.com/Sysforums/posts/preList/3959/20641.page</guid>
				<link>http://www.sysaid.com/Sysforums/posts/preList/3959/20641.page</link>
				<pubDate><![CDATA[Fri, 21 May 2010 20:05:32]]> GMT</pubDate>
				<author><![CDATA[ HealthCare Support Staff]]></author>
			</item>
			<item>
				<title>Re:Major security hole - Domain Administrator Password</title>
				<description><![CDATA[ Hey guys,<br /> <br /> I wanted to jump into the conversation with some news:<br /> <br /> 1. The LDAP information that appears in the serverConf.xml file is not being looked at by the SysAid Server. This information is securely saved in the database. It is showing in the serverConf.xml file for historical reasons. If you setup a new installation of SysAid, it should not store that information in that file. Existing customers that have that information in their serverConf.xml file, could safely remove all lines from &lt;LDAPConf&gt; until &lt;/LDAPConf&gt;.<br /> <br /> 2. The password for the database connection &lt;dbPassword&gt;, which was also stored in clear text, is now (7.0) encrypted in the serverConf.xml file.<br /> <br /> I'll keep my eyes on this post, so if anyone has a question...<br /> Joseph]]></description>
				<guid isPermaLink="true">http://www.sysaid.com/Sysforums/posts/preList/3959/20654.page</guid>
				<link>http://www.sysaid.com/Sysforums/posts/preList/3959/20654.page</link>
				<pubDate><![CDATA[Sun, 23 May 2010 09:21:14]]> GMT</pubDate>
				<author><![CDATA[ Joseph Zargari]]></author>
			</item>
			<item>
				<title>Re:Major security hole - Domain Administrator Password</title>
				<description><![CDATA[ [quote=Joseph Zargari]Hey guys,<br /> <br /> I wanted to jump into the conversation with some news:<br /> <br /> 1. The LDAP information that appears in the serverConf.xml file is not being looked at by the SysAid Server. This information is securely saved in the database. It is showing in the serverConf.xml file for historical reasons. If you setup a new installation of SysAid, it should not store that information in that file. Existing customers that have that information in their serverConf.xml file, could safely remove all lines from &lt;LDAPConf&gt; until &lt;/LDAPConf&gt;.<br /> <br /> 2. The password for the database connection &lt;dbPassword&gt;, which was also stored in clear text, is now (7.0) encrypted in the serverConf.xml file.<br /> <br /> I'll keep my eyes on this post, so if anyone has a question...<br /> Joseph[/quote]<br /> <br /> Dear Joseph<br /> <br /> Can you think of a good reason not telling your clients this info earlier?<br /> If there was a security issue and it was fixed in new install and upgraded users needed to do any action I would expect Ilient to tell about it ....<br /> Just my 2 cents.<br /> <br /> Lev]]></description>
				<guid isPermaLink="true">http://www.sysaid.com/Sysforums/posts/preList/3959/20951.page</guid>
				<link>http://www.sysaid.com/Sysforums/posts/preList/3959/20951.page</link>
				<pubDate><![CDATA[Mon, 31 May 2010 09:06:04]]> GMT</pubDate>
				<author><![CDATA[ Lev]]></author>
			</item>
			<item>
				<title>Re:Major security hole - Domain Administrator Password</title>
				<description><![CDATA[ Hey Lev,<br /> <br /> Basically, we never looked at this as a security issue. Since SysAid usually runs on a server, the serverConf.xml file should not be accessible for domain users to see (limited by NTFS permissions).<br /> The password showing on the configuration file was more of a cosmetic issue.<br /> <br /> Jospeh.<br /> ]]></description>
				<guid isPermaLink="true">http://www.sysaid.com/Sysforums/posts/preList/3959/20973.page</guid>
				<link>http://www.sysaid.com/Sysforums/posts/preList/3959/20973.page</link>
				<pubDate><![CDATA[Tue, 1 Jun 2010 06:22:29]]> GMT</pubDate>
				<author><![CDATA[ Joseph Zargari]]></author>
			</item>
			<item>
				<title>Re:Major security hole - Domain Administrator Password</title>
				<description><![CDATA[ I hate to dig up an old ticket but the responses to peoples questions in this thread are inadequate.<br /> <br /> We are being told to use a service account with read-only privileges, however for password services you ask that we use a domain administrator account. what is the correct answer? Domain admin or read-only user?]]></description>
				<guid isPermaLink="true">http://www.sysaid.com/Sysforums/posts/preList/3959/38023.page</guid>
				<link>http://www.sysaid.com/Sysforums/posts/preList/3959/38023.page</link>
				<pubDate><![CDATA[Tue, 5 Mar 2013 20:34:17]]> GMT</pubDate>
				<author><![CDATA[ @@@]]></author>
			</item>
			<item>
				<title>Re:Major security hole - Domain Administrator Password</title>
				<description><![CDATA[ Hi @@@,<br /> SysAid requires read-only permissions to import user data from AD and perform authentication. It requires a domain admin account if you are also implementing Password Services.<br /> <br /> I hope this answers your question.<br /> Joseph.]]></description>
				<guid isPermaLink="true">http://www.sysaid.com/Sysforums/posts/preList/3959/38039.page</guid>
				<link>http://www.sysaid.com/Sysforums/posts/preList/3959/38039.page</link>
				<pubDate><![CDATA[Thu, 7 Mar 2013 10:42:11]]> GMT</pubDate>
				<author><![CDATA[ Joseph Zargari]]></author>
			</item>
			<item>
				<title>Re:Major security hole - Domain Administrator Password</title>
				<description><![CDATA[ So did you ever notify your customers or do they only find out when they stumble across this post? Storing any password in plaintext is poor security and if you didn’t think this was an issue or worth notifying your clients about then what other “non-issues” are lurking out there for us to find?<br /> <br /> Unacceptable.<br /> ]]></description>
				<guid isPermaLink="true">http://www.sysaid.com/Sysforums/posts/preList/3959/38694.page</guid>
				<link>http://www.sysaid.com/Sysforums/posts/preList/3959/38694.page</link>
				<pubDate><![CDATA[Tue, 14 May 2013 12:32:23]]> GMT</pubDate>
				<author><![CDATA[ Tarphon]]></author>
			</item>
			<item>
				<title>Re:Major security hole - Domain Administrator Password</title>
				<description><![CDATA[ Hi Tarphon,<br /> <br /> Since this post started, this was already corrected. SysAid doesn't store any password in plain text in the config files, definitely not the domain admin's one.<br /> <br /> We take security very seriously when we come to plan, design and develop our products. We spend great deal of efforts and resources making SysAid more secure.<br /> Surely, things can go wrong - but we are always ready to respond quickly when a security breach is found.<br /> <br /> Thanks,<br /> Joseph.]]></description>
				<guid isPermaLink="true">http://www.sysaid.com/Sysforums/posts/preList/3959/38731.page</guid>
				<link>http://www.sysaid.com/Sysforums/posts/preList/3959/38731.page</link>
				<pubDate><![CDATA[Sat, 18 May 2013 19:47:12]]> GMT</pubDate>
				<author><![CDATA[ Joseph Zargari]]></author>
			</item>
	</channel>
</rss>