Bug 469 - Password field shows contents when running SQLPLUS in SSH shell
Summary: Password field shows contents when running SQLPLUS in SSH shell
Status: CLOSED INVALID
Alias: None
Product: Portable OpenSSH
Classification: Unclassified
Component: sshd (show other bugs)
Version: -current
Hardware: ix86 Cygwin on NT/2k/Win7-11
: P2 security
Assignee: OpenSSH Bugzilla mailing list
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2003-01-17 02:36 AEDT by Robert Ozark
Modified: 2004-04-14 12:24 AEST (History)
0 users

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Ozark 2003-01-17 02:36:33 AEDT
When entering passwords, after initial login sequence, the contents of 
the "password:' field echo to the screen. This happens when accessing the 
server with SSH. If I use a DOS shell locally, the problem doesn't occur. 
Initially, I use VanDyke's SecureCRT to call the server and initialize the 
shell. When I do this to a UNIX server (using Sun Solaris 2.6/2.8), there is no 
problem. This occurs when accessing a server using a Windows O/S. All 
initialization parameters for SSH have been checked and customizable sections 
of SecureCRT have been verified as set properly (in communication with 
VanDyke). This is affecting Admin duties on these servers due to critical 
passwords showing on the screens. Thank you for your help.  Robert
Comment 1 Markus Friedl 2003-01-26 22:39:50 AEDT
sorry, what exactly are you doing?
Comment 2 Robert Ozark 2003-05-07 04:54:49 AEST
Sorry for the delay in getting back to you, but I just got back to working on 
NT problems.

Problem: when I login to my NT4.0 server, using VanDyke's SecureCRT4.0 and 
SSH2, I get the usual screen. All seems well. Now I connect to the Oracle 
component using SQLPlus*:

sqlplus system@DBname

When the password prompt appears:

Enter password:

I type in the password and viola!!! the password appears on the screen!

I try to use a password file (sort of like an .INI file) and the password again 
shows up on the screen. Needless to say, this compromises my security a tad ;-}

What I need is:

1) a fix
2) an explanation or
3) a way of using SQLPlus* for Oracle with SSH2

I don't know how else to explain this problem.

I appreciate your help


Robert
Oracle DBA
Comment 3 Damien Miller 2003-07-03 18:14:10 AEST
Which is the client (secure CRT or OpenSSH)? Which is the server? (I assume that
OpenSSH is the server)

Does the problem happen when you use openssh on the client end?

Can you replicate this with any other programs? E.g. one of the cygwin passwd
utils. 
Comment 4 Damien Miller 2004-02-10 13:30:30 AEDT
No reply in 8 months = no bug
Comment 5 Damien Miller 2004-04-14 12:24:18 AEST
Mass change of RESOLVED bugs to CLOSED