RMA password in clear text

Remote Monitoring Agent for Linux, FreeBSD, and other UNIX-like platforms.
Post Reply
RicochetPeter
Posts: 10
Joined: Mon Feb 26, 2007 7:56 am

RMA password in clear text

Post by RicochetPeter »

Hi KS-Soft,

I see that the windows RMA hides its password in two lines of text which are somewhat cryptic, whereas the Linux RMA uses the password in clear text. This looks like a little security hole to me. Is it possible to have it in a similar form as in the Windows RMA?
KS-Soft Europe
Posts: 2832
Joined: Tue May 16, 2006 4:41 am
Contact:

Re: RMA password in clear text

Post by KS-Soft Europe »

RicochetPeter wrote:This looks like a little security hole to me.
I do not think so. All traffic between RMA and HostMonitor or RMA and RMA Manager is encrypted using MD5 + Twofish encryption and the password itself is never transmitted through the network without encryption.

Regards,
Max
RicochetPeter
Posts: 10
Joined: Mon Feb 26, 2007 7:56 am

Post by RicochetPeter »

Having it in the config file (rma.ini) in clear text is what I would like to prevent...
KS-Soft
Posts: 12821
Joined: Wed Apr 03, 2002 6:00 pm
Location: USA
Contact:

Post by KS-Soft »

Probably we will change that in the future.
On the other hand
1) if somebody has access to your system, he can make a lot of problems without knowing this password
2) You may restrict access to this file

Regards
Alex
RicochetPeter
Posts: 10
Joined: Mon Feb 26, 2007 7:56 am

Post by RicochetPeter »

thx :)
Post Reply