• mailsrvr logs POP3/SMTP AUTH credentials, ignoring SM_ECHO_PW

    From Rob Swindell@1:103/705 to GitLab issue in main/sbbs on Tue Sep 29 13:27:40 2026
    open https://gitlab.synchro.net/main/sbbs/-/work_items/1267

    The mail server writes client credentials to its log in plaintext or base64 (which is trivially decodable), and ignores the "Display/Log Passwords Locally" system option (`SM_ECHO_PW`) for these lines. Anyone who can read the server log can recover SMTP AUTH and POP3 passwords for every account that authenticates.

    Line numbers below are for `src/sbbs3/mailsrvr.cpp` at 826fe27664 (2026-09-28).

    ## Logged only when `DEBUG_RX_RSP` is set in the mail server Options

    - **POP3 `PASS <password>`** (plaintext): read via `sockgetrsp(..., "PASS ", ...)` at line 1389, which logs the whole line as `RX: PASS ...` at line 646.
    - **SMTP `AUTH LOGIN`** username and password (base64): lines 4447 and 4460.
    - **SMTP `AUTH PLAIN`** response to the server's `334` challenge (base64 of `authzid\0user\0password`): line 4479.
    - **SMTP `AUTH CRAM-MD5`** response: line 4589. It contains the username and an HMAC of the challenge rather than the password, so this one is low risk.

    `DEBUG_RX_RSP` reads like "show server responses" (and is also used for the RX side of outbound SEND sessions), so a sysop enabling it for delivery troubleshooting won't expect it to log the credentials of inbound clients.

    ## Logged regardless of options

    - **SMTP `AUTH PLAIN <base64>`** with the initial response on the command line (RFC 4954): every SMTP command is logged at LOG_DEBUG by line 4394 before it is parsed, credentials included.
    - **LOG_NOTICE** error paths log the raw argument: `!Bad AUTH LOGIN password argument: %s` (4462), `!Bad AUTH PLAIN argument: %s` (4484) and `!Bad AUTH CRAM-MD5 response: %s` (4592). A client that sends a slightly malformed password gets it written to the log at NOTICE.

    ## Observed

    On a production host with `DEBUG_RX_RSP` enabled, the current log contained hundreds of `POP3 ... RX: PASS ...` lines plus `AUTH LOGIN` and `AUTH PLAIN` credential lines. That included the SMTP submission password of an application that sends mail through the server, going back as far as the rotated logs reach.

    ## Suggested fix

    Redact the credential-bearing lines unless `SM_ECHO_PW` is set, the same way the POP3/SMTP password-failure messages already do (e.g. mailsrvr.cpp lines 1399, 1436, 4508, 4530):

    - log `RX: PASS <redacted>` for POP3 `PASS`;
    - log `RX: <credentials>` for the AUTH LOGIN/PLAIN/CRAM-MD5 response lines;
    - in the line-4394 command log, truncate `AUTH PLAIN <initial-response>` to `AUTH PLAIN <credentials>`;
    - drop the raw argument from the three `!Bad AUTH ...` NOTICE messages, or gate it on `SM_ECHO_PW`.

    Sysops who have run with `DEBUG_RX_RSP` enabled should consider their mail server logs sensitive and rotate the passwords of accounts that authenticate to it (application/submission accounts in particular).

    -- *Authored by Claude (Claude Code), on behalf of @rswindell*
    --- SBBSecho 3.37-Linux
    * Origin: Vertrauen - [vert/cvs/bbs].synchro.net (1:103/705)
  • From Rob Swindell@1:103/705 to GitLab issue in main/sbbs on Wed Sep 30 19:08:49 2026
    close https://gitlab.synchro.net/main/sbbs/-/work_items/1267
    --- SBBSecho 3.38-Linux
    * Origin: Vertrauen - [vert/cvs/bbs].synchro.net (1:103/705)