duplicity-team team mailing list archive
-
duplicity-team team
-
Mailing list archive
-
Message #00193
[Bug 504423] [NEW] duplicity shows sensitive data in process listing
*** This bug is a security vulnerability ***
Private security bug reported:
If credentials are given in the command line url parameter these show up
in 'ps'
e.g.
/usr/bin/duplicity --verbosity 4 --encrypt-key FD3846C2 --sign-key
FD3846C2 --gpg-options= --exclude-globbing-filelist
/root/.duply/bkp/exclude /backup/
ftp://<user>:<PASSWORT>@<backupserver>/backup
suggestion is to introduce env vars URL_PASSWORD/URL_USERNAME and to
keep FTP_PASSWORD for ftp backend only and backward compatibility. The
fact that FTP_BACKEND can be used with nearly all backend is afaik not
documented. Even so duply 1.5.1.4+ will use it until this bug is
resolved.
for the future a config file based auth as mentioned in
http://lists.gnu.org/archive/html/duplicity-talk/2010-01/msg00032.html
could make sense.
.. ede
** Affects: duplicity
Importance: Undecided
Status: New
--
duplicity shows sensitive data in process listing
https://bugs.launchpad.net/bugs/504423
You received this bug notification because you are a member of
duplicity-team, which is a direct subscriber.
Status in duplicity - Bandwidth Efficient Encrypted Backup: New
Bug description:
If credentials are given in the command line url parameter these show up in 'ps'
e.g.
/usr/bin/duplicity --verbosity 4 --encrypt-key FD3846C2 --sign-key FD3846C2 --gpg-options= --exclude-globbing-filelist /root/.duply/bkp/exclude /backup/ ftp://<user>:<PASSWORT>@<backupserver>/backup
suggestion is to introduce env vars URL_PASSWORD/URL_USERNAME and to keep FTP_PASSWORD for ftp backend only and backward compatibility. The fact that FTP_BACKEND can be used with nearly all backend is afaik not documented. Even so duply 1.5.1.4+ will use it until this bug is resolved.
for the future a config file based auth as mentioned in
http://lists.gnu.org/archive/html/duplicity-talk/2010-01/msg00032.html
could make sense.
.. ede
Follow ups
-
[Bug 504423] Re: duplicity shows sensitive data in process listing
From: Kenneth Loafman, 2020-09-29
-
[Bug 504423] Re: duplicity shows sensitive data in process listing
From: Eugene Crosser, 2012-11-17
-
[Bug 504423] Re: duplicity shows sensitive data in process listing
From: edso, 2012-11-17
-
[Bug 504423] Re: duplicity shows sensitive data in process listing
From: Eugene Crosser, 2012-11-17
-
[Bug 504423] Re: duplicity shows sensitive data in process listing
From: edso, 2012-11-17
-
[Bug 504423] Re: duplicity shows sensitive data in process listing
From: den, 2012-11-17
-
[Bug 504423] Re: duplicity shows sensitive data in process listing
From: papukaija, 2012-09-30
-
[Bug 504423] Re: duplicity shows sensitive data in process listing
From: Eugene Crosser, 2012-06-08
-
[Bug 504423] Re: duplicity shows sensitive data in process listing
From: Eugene Crosser, 2012-06-08
-
[Bug 504423] Re: duplicity shows sensitive data in process listing
From: Eugene Crosser, 2012-06-08
-
[Bug 504423] Re: duplicity shows sensitive data in process listing
From: edso, 2012-06-08
-
[Bug 504423] Re: duplicity shows sensitive data in process listing
From: Eugene Crosser, 2012-06-08
-
[Bug 504423] Re: duplicity shows sensitive data in process listing
From: Raphaël Droz, 2011-10-03
-
[Bug 504423] Re: duplicity shows sensitive data in process listing
From: Kenneth Loafman, 2011-08-17
-
[Bug 504423] Re: duplicity shows sensitive data in process listing
From: edso, 2011-07-02
-
[Bug 504423] Re: duplicity shows sensitive data in process listing
From: edso, 2011-06-14
-
[Bug 504423] Re: duplicity shows sensitive data in process listing
From: Kenneth Loafman, 2011-06-14
-
[Bug 504423] Re: duplicity shows sensitive data in process listing
From: Kenneth Loafman, 2011-06-13
-
[Bug 504423] Re: duplicity shows sensitive data in process listing
From: Kenneth Loafman, 2011-04-02
-
[Bug 504423] Re: duplicity shows sensitive data in process listing
From: Kenneth Loafman, 2011-03-06
-
[Bug 504423] Re: duplicity shows sensitive data in process listing
From: Daniel Hahler, 2011-01-09
-
[Bug 504423] Re: duplicity shows sensitive data in process listing
From: Kenneth Loafman, 2010-09-19
-
[Bug 504423] Re: duplicity shows sensitive data in process listing
From: Kenneth Loafman, 2010-09-06
-
[Bug 504423] Re: duplicity shows sensitive data in process listing
From: edso, 2010-01-08
-
[Bug 504423] Re: duplicity shows sensitive data in process listing
From: edso, 2010-01-08
-
[Bug 504423] Re: duplicity shows sensitive data in process listing
From: edso, 2010-01-08
-
[Bug 504423] Re: duplicity shows sensitive data in process listing
From: Peter Schuller, 2010-01-08
-
[Bug 504423] [NEW] duplicity shows sensitive data in process listing
From: edso, 2010-01-07
References