Bug Credential exposure
#1
1. Edit existing smb entry
2. Fill in invalid hostname (maybe invalid share)
3. See plain password from the UI

Image
Reply
#2
The reproduction misses step 4 - try to enter the wrongly added source - after wards it will expose the credentials...
AppleTV4/iPhone/iPod/iPad: HowTo find debug logs and everything else which the devs like so much: click here
HowTo setup NFS for Kodi: NFS (wiki)
HowTo configure avahi (zeroconf): Avahi_Zeroconf (wiki)
READ THE IOS FAQ!: iOS FAQ (wiki)
Reply
#3
sorry i don't know what you mean. by "enter the source". in my case it exposed the credentials right after i clicked okay in step 2, or is it the "click okay" you are missing?
Reply
#4
Thx for the report - fix is proposed for inclusion here:

https://github.com/xbmc/xbmc/pull/8768

I needed to try to enter the newly edited source before the disclosure happend (after clicking away the following timeout dialog). Might be small platform differences ..
AppleTV4/iPhone/iPod/iPad: HowTo find debug logs and everything else which the devs like so much: click here
HowTo setup NFS for Kodi: NFS (wiki)
HowTo configure avahi (zeroconf): Avahi_Zeroconf (wiki)
READ THE IOS FAQ!: iOS FAQ (wiki)
Reply
#5
Ha. That's a bug I had for long time but never figured out how I actually triggered it.
Read/follow the forum rules.
For troubleshooting and bug reporting, read this first
Interested in seeing some YouTube videos about Kodi? Go here and subscribe
Reply
#6
And its there since 2009 or even earlier (allthekillers move linux port to trunk commit at least)
AppleTV4/iPhone/iPod/iPad: HowTo find debug logs and everything else which the devs like so much: click here
HowTo setup NFS for Kodi: NFS (wiki)
HowTo configure avahi (zeroconf): Avahi_Zeroconf (wiki)
READ THE IOS FAQ!: iOS FAQ (wiki)
Reply

Logout Mark Read Team Forum Stats Members Help
Credential exposure0