open
https://gitlab.synchro.net/main/sbbs/-/work_items/1267
The mail server writes client credentials to its log in plaintext or base64 (which is trivially decodable), and ignores the "Display/Log Passwords Locally" system option (`SM_ECHO_PW`) for these lines. Anyone who can read the server log can recover SMTP AUTH and POP3 passwords for every account that authenticates.
Line numbers below are for `src/sbbs3/mailsrvr.cpp` at 826fe27664 (2026-09-28).
## Logged only when `DEBUG_RX_RSP` is set in the mail server Options
- **POP3 `PASS <password>`** (plaintext): read via `sockgetrsp(..., "PASS ", ...)` at line 1389, which logs the whole line as `RX: PASS ...` at line 646.
- **SMTP `AUTH LOGIN`** username and password (base64): lines 4447 and 4460.
- **SMTP `AUTH PLAIN`** response to the server's `334` challenge (base64 of `authzid\0user\0password`): line 4479.
- **SMTP `AUTH CRAM-MD5`** response: line 4589. It contains the username and an HMAC of the challenge rather than the password, so this one is low risk.
`DEBUG_RX_RSP` reads like "show server responses" (and is also used for the RX side of outbound SEND sessions), so a sysop enabling it for delivery troubleshooting won't expect it to log the credentials of inbound clients.
## Logged regardless of options
- **SMTP `AUTH PLAIN <base64>`** with the initial response on the command line (RFC 4954): every SMTP command is logged at LOG_DEBUG by line 4394 before it is parsed, credentials included.
- **LOG_NOTICE** error paths log the raw argument: `!Bad AUTH LOGIN password argument: %s` (4462), `!Bad AUTH PLAIN argument: %s` (4484) and `!Bad AUTH CRAM-MD5 response: %s` (4592). A client that sends a slightly malformed password gets it written to the log at NOTICE.
## Observed
On a production host with `DEBUG_RX_RSP` enabled, the current log contained hundreds of `POP3 ... RX: PASS ...` lines plus `AUTH LOGIN` and `AUTH PLAIN` credential lines. That included the SMTP submission password of an application that sends mail through the server, going back as far as the rotated logs reach.
## Suggested fix
Redact the credential-bearing lines unless `SM_ECHO_PW` is set, the same way the POP3/SMTP password-failure messages already do (e.g. mailsrvr.cpp lines 1399, 1436, 4508, 4530):
- log `RX: PASS <redacted>` for POP3 `PASS`;
- log `RX: <credentials>` for the AUTH LOGIN/PLAIN/CRAM-MD5 response lines;
- in the line-4394 command log, truncate `AUTH PLAIN <initial-response>` to `AUTH PLAIN <credentials>`;
- drop the raw argument from the three `!Bad AUTH ...` NOTICE messages, or gate it on `SM_ECHO_PW`.
Sysops who have run with `DEBUG_RX_RSP` enabled should consider their mail server logs sensitive and rotate the passwords of accounts that authenticate to it (application/submission accounts in particular).
-- *Authored by Claude (Claude Code), on behalf of @rswindell*
--- SBBSecho 3.37-Linux
* Origin: Vertrauen - [vert/cvs/bbs].synchro.net (1:103/705)