Last modified: 2012-08-05 12:35:46 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T40909, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 38909 - Typo shows Username and Password in log
Typo shows Username and Password in log
Status: RESOLVED INVALID
Product: MediaWiki extensions
Classification: Unclassified
Other (Other open bugs)
REL1_18-branch
All All
: Unprioritized enhancement (vote)
: ---
Assigned To: Nobody - You can work on this!
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2012-08-01 07:51 UTC by carchaias
Modified: 2012-08-05 12:35 UTC (History)
1 user (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description carchaias 2012-08-01 07:51:03 UTC
Currently MW shows userenames that are not present in the log. That could leak passwords to the log if the user did not safely hit the "tab" or klicks within the password field on login. In my wikilog I found an entry similar to this:

13:16, 28 June 2012 WikiSysop (Talk | contribs | block) Fehler beim Login ‎ (Der Benutzername „AnyusernameAnypassword“ ist nicht vorhanden. Bitte überprüfen Sie die Schreibweise.)

IMHO it would be more safe to reflect something like: A User with IP xxx.xxx.xxx.xxx entered an unknown username.
Comment 1 Alexandre Emsenhuber [IAlex] 2012-08-05 07:56:19 UTC
MediaWiki does not log login attempts, successful or not. Aren't you using an extension to do this?
Comment 2 carchaias 2012-08-05 12:34:16 UTC
Oops, of course it is the UserLoginlog extension doing this. Sorry.....

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links