8 ms·
Yes and it makes reading your logs needlessly harder. Sometimes I find an odd password being probed, search for it on the web and find an interesting story, tha
by dmesg 1y ago
Yes and it makes reading your logs needlessly harder. Sometimes I find an odd password being probed, search for it on the web and find an interesting story, that a new backdoor was discovered in a commercial appliance.
In that regard reading my logs led me sometimes to interesting articles about cyber security. Also log flooding may result in your journaling service truncating the log and you miss something important.
- wvbdmp 1y agoYou log passwords?
- deleted 1y ago[deleted]
- zeta0134 1y agoJust about nobody logs passwords on purpose. But really stupid IoT devices accept credentials as like query strings, or part of the path or something, and it's common to log those. The attacker is sending you passwords meant for a much less secure system.
- SoftTalker 1y agoYou probably shouldn't log usernames then, or really any form fields, as users might accidentally enter a password into one of them. Kind of defeats the point of web forms, but safety is important!
- Dylan16807 1y agoAre you using a very weird definition of "logging" to make a joke? Web forms don't need any logging to work.
- SoftTalker 1y agoYou save them in a database. Probably in clear text. Six of one, half-dozen of the other.
- Dylan16807 1y agoA password being put into a normal text field in a properly submitted form is a lot less likely than getting into some query or path. And a database is more likely to be handled properly than some random log file. Six of one, .008 of a dozen of the other.
- hinkley 1y agoSo no access logs at all then? That sounds effective.
- stronglikedan 1y agoSure, why not. Log every secret you come across (or that comes across you). Just don't log your own secrets. Like OP said, it lead down some interesting trails.
- dpkirchner 1y agoI remember back before ssh was a thing folks would log login attempts -- it was easy to get some people's passwords because it was common for them to accidentally use them as the username (which are always safe to log, amirite?). All you had to do was watch for a failed login followed by a successful login from the same IP.
- deleted 1y ago[deleted]
- rollcat 1y ago> Sometimes I find an odd password being probed, search for it on the web and find an interesting story [...]. Yeah, this is beyond irresponsible. You know the moment you're pwned, __you__ become the new interesting story? For everyone else, use a password manager to pick a random password for everything.
- Thorrez 1y agoWhat is beyond irresponsible? Monitoring logs and researching odd things found there?
- JohnFen 1y agoHow are passwords ending up in your logs? Something is very, very wrong there.
- dmesg 1y agoDoes an attacking bot know your webserver is not a misconfigured router exposing its web interface to the net? I often am baffled what conclusions people come up with from half reading posts. I had bots attack me with SSH 2.0 login attempts on port 80 and 443. Some people underestimate how bad at computer science some skids are.
- socksy 1y agoAlso baffled that three separate people came to that conclusion. Do they not run web servers on the open web or something? Script kiddies are constantly probing urls, and urls come up in your logs. Sure it would be bad if that was how your app was architected. But it's not how it's architected, it's how the skids hope your app is architected. It's not like if someone sends me a request for /wp-login.php that my rails app suddenly becomes WordPress??
- JohnFen 1y ago> Do they not run web servers on the open web or something? Until AI crawlers chased me off of the web, I ran a couple of fairly popular websites. I just so rarely see anybody including passwords in the URLs anymore that I didn't really consider that as what the commenter was talking about.