4 ms·
seriously? pretty easily. somebody probably left a debug log message in place or something. guaranteed that this happens all the time and most people don't repo
by thln666 8y ago
seriously? pretty easily. somebody probably left a debug log message in place or something. guaranteed that this happens all the time and most people don't report it.
- weavie 8y agoIndeed. This is probably a good reminder for every developer to just go and check through their logs to see what is there. It can be quite a shock sometimes to find how much can get dumped there..
- jonjojr 8y agoAs developer, I can tell you this happens more often than I'd like to admit. debug logs is that necessary evil you need to troubleshoot pesky bugs. Unfortunately some of these debug tools need to be turned on in a live environment to capture those logs for debugging. But also Unfortunately, we are humans and we concentrate on fixing the bug and forget to turn off logging or log unnecessary data.
- chatmasta 8y agoI doubt anyone left something that logged the plaintext password. No reasonable architecture necessitates holding onto a plaintext password for more than one line of code. One possibility is an HTTP server on the request path after TLS termination. But then why is an HTTP server logging the request body? My guess would be some sort of instrumentation process was blindly reading data in memory without distinguishing what the data was, but produced logs that incidentally included passwords.
- miragle 8y agomany reasonable architectures funnel the request body through multiple middlewares before it reaches the code that actually needs the password. there are so many places that request data can be logged in any reasonable system. this is completely ordinary. it's not like there's a special HTTP mechanism for transmitting passwords that keeps it out of the normal code flow. it's in the request. if you log requests, you're probably going to end up accidentally logging something you're not supposed to at some point.
- testplzignore 8y agoIn my experience, I've seen both of the following scenarios: POST request comes in from the client. Full URL and request body is logged. Sometimes for simply troubleshooting, sometimes for security reasons (e.g., wanting to know all data coming in so that it's possible to identify security holes after they've been exploited). POST request comes in from client. Frontend server makes a GET request to a backend server, and the password ends up in the standard request logs. In one case, I've seen this happen because the developer thought path variables were cool, so every API they wrote looked like /a/b/c/d/e. Sigh.
- bdamm 8y agoAbsolutely this happens all the time. I personally have seen it happen twice at two different companies.