Jump to content
hozarares

Pidgin stores account data in plaintext!

Recommended Posts

Posted

I was just looking for some configuration files in Pidgins working directory "~/.purple/" and found this:

1....

2.-rw------- 1 victor users 22939 Nov 23 19:34 accounts.xml

3....

Well I wouldn't have payed to much attention at that file, if it had not contained this:

01.$ head accounts.xml

02.<?xml version='1.0' encoding='UTF-8' ?>

03.

04.<ACCOUNT version="1.0">

05. <ACCOUNT>

06. <PROTOCOL>prpl-msn</PROTOCOL>

07. <NAME>******@hotmail.de</NAME>

08. <PASSWORD>**</PASSWORD>

09. <ALIAS>v****</ALIAS>

10. <STATUSES>

11.

12....

Plaintext passwords? I couldn't believe it. So I searched on Pidgins Wiki site for some entries justifing this (in)secure measurement. And indeed I found one:PlainTextPasswords ? Pidgin ? Trac

Acest mic articol l`am luat de pe un site....da nu`l mai gasesc .....

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...