RE: (RADIATOR) 2.16.1 LOG question (IMPORTANT)

2000-07-18 Thread Charles Sprickman
On Mon, 17 Jul 2000, Ingvar Berg (ERA) wrote: [my message regarding leaving a password log with only fails and no encrypted strings] > Please don't forget that most failed pw entries are correct except for > one or two chars => this info can be quite interesting to an intruder > (extenal or "ins

RE: (RADIATOR) 2.16.1 LOG question (IMPORTANT)

2000-07-17 Thread Ingvar Berg (ERA)
> -Original Message- > From: Charles Sprickman [mailto:[EMAIL PROTECTED]] > SNIP - > > What I'd like to see is an option in the password logging to only log > failed attempts showing the username, time, and the password the > user entered. This would be a wonderful tool to give

Re: (RADIATOR) 2.16.1 LOG question (IMPORTANT)

2000-06-23 Thread Charles Sprickman
Two ideas I'm thinking of... -While I'm testing out radiator with radpwtst (a wonderful tool, BTW) and then later on one chassis, I found the password logging feature to be a wonderful final test to see that folks were actually getting in. When I showed it to the support people, they got really

Re: (RADIATOR) 2.16.1 LOG question (IMPORTANT)

2000-06-23 Thread Hugh Irvine
Hello Brian, Darwin, and everyone else who is interested in Logging - Well, you just can't win. The log level of some events was changed for some events at the request of some of our customers (obviously not you ). If this is a real problem, all I can suggest is that you troll through the co