Skip to main content
ExLibris

Knowledge Assistant

BETA
 
  • Subscribe by RSS
  • Back
    Aleph

     

    Ex Libris Knowledge Center
    1. Search site
      Go back to previous article
      1. Sign in
        • Sign in
        • Forgot password
    1. Home
    2. Aleph
    3. Knowledge Articles
    4. Passwords appear in clear-text in apache log and renewal URL

    Passwords appear in clear-text in apache log and renewal URL

    1. Last updated
    2. Save as PDF
    3. Share
      1. Share
      2. Tweet
      3. Share
    No headers
    • Article Type: General
    • Product: Aleph
    • Product Version: 18.01

    Description:
    Our users have been sending a URL such as: http://il-aleph07.corp.exlibrisgroup.com:8993/F?func=bor-info to our www_server, which prompts them for a username/password, and then takes them to the My Library Card screen where they can renew their items on loan.

    The unencrypted password is exposed in two places in this scenario: the URL in which they enter the password (as seen in the www_server log) and in the apache log.

    Resolution:
    We suggested that they have the users follow the "normal" path: connect to OPAC, log-in, and do My Library Card.

    The site "removed the direct link to Loans and now require users to go through the normal Catalog login, then My Library Card, etc.. Passwords no longer appear on the URL. The problem with passwords appearing in the apache log file was a direct result of that URL, so both problems have now been resolved."


    • Article last edited: 10/8/2013
    View article in the Exlibris Knowledge Center
    1. Back to top
      • Password not verified on connectable..User name does not exist" for certain login's
      • PATH and LD_LIBRARY_PATH in aleph_start
    • Was this article helpful?

    Recommended articles

    1. Article type
      Topic
      Language
      English
      Product
      Aleph
    2. Tags
      1. 18.01
      2. contype:kba
      3. Prod:Aleph
      4. Type:General
    1. © Copyright 2025 Ex Libris Knowledge Center
    2. Powered by CXone Expert ®
    • Term of Use
    • Privacy Policy
    • Contact Us
    2025 Ex Libris. All rights reserved