<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=29&amp;t=946" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2013-02-07T15:13:31+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=29&amp;t=946</id>
<entry>
<author><name><![CDATA[Tom]]></name></author>
<updated>2013-02-07T15:13:31+01:00</updated>
<published>2013-02-07T15:13:31+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=946&amp;p=3566#p3566</id>
<link href="https://forum.yubico.com/viewtopic.php?t=946&amp;p=3566#p3566"/>
<title type="html"><![CDATA[Re: [BUG] Yubiradius 3.6.0 logs all passwords in plaintext]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=946&amp;p=3566#p3566"><![CDATA[
Hello again,<br /><br />This will be fixed in version 3.6.1 which will be released soon.<br /><br />Thank you for your post.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2195">Tom</a> — Thu Feb 07, 2013 3:13 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[ronsdavis]]></name></author>
<updated>2013-02-06T20:16:03+01:00</updated>
<published>2013-02-06T20:16:03+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=946&amp;p=3560#p3560</id>
<link href="https://forum.yubico.com/viewtopic.php?t=946&amp;p=3560#p3560"/>
<title type="html"><![CDATA[[BUG] Yubiradius 3.6.0 logs all passwords in plaintext]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=946&amp;p=3560#p3560"><![CDATA[
The current release of YubiRadius logs all requests to /var/log/syslog and /var/log/debug<br />The log entries appear as follows<br />syslog:Feb  5 19:37:28 yubiradius3 ykropval[2955]: LOG_DEBUG:ykropval-verify:[127.0.0.1] Request: user=rdavis&amp;password=DOGBREATH&amp;otp=vvxxxxxxdieflrccltlhxxxxjdrfbxxxxgcnnljbdvrl<br /><br />In order to change this edit /usr/share/ykropval/ykropval-verify.php<br />Line 19 reads<br />$myLog-&gt;log(LOG_DEBUG, &quot;Request: &quot; . $_SERVER['QUERY_STRING']); <br />Either comment out the line, or remove . $_SERVER['QUERY_STRING']<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2288">ronsdavis</a> — Wed Feb 06, 2013 8:16 pm</p><hr />
]]></content>
</entry>
</feed>