3 ms·
I've seen this scenario unfold before: 1. User provides username/password. 2. An exception occurs somewhere. 3. The stack trace from the exception is log
by CiPHPerCoder 8y ago
I've seen this scenario unfold before:
1. User provides username/password.
2. An exception occurs somewhere.
3. The stack trace from the exception is logged.
4. The stack trace includes the credentials.
5. The exception ends up in a ticketing system (Trac, JIRA, etc.)
6. Nobody notices for years.
- testplzignore 8y agoAs a bonus, sometimes the stack trace will be returned to the user, and maybe it'll contain server-side secrets, too!
- beberlei 8y agoOr all the environment variables containing tons of password+tokens, or in javascript libraries all the headers, including cookies that could be used to overtake a session. Error/Exception tracking software is quite dangerous if it written with a "lets store everything, because it could help find the problem" mindest.
- dwyerm 8y agoWhen I was doing some consulting via RDP, I made sure to inform the client that I was about to expose things. "I am about to run strace on this web server instance. This is going to show what all the system calls are doing and how long they're taking. It is going to make the performance of this one instance very poor. It is possible that this will print private information like passwords and credit card numbers in clear text. Are you okay with this?" I'm not sure they fully understood what they were acknowledging, but I heard back later that they were impressed with my professionalism.