From c297ea97e288da16216d5c121ddefa7b61923847 Mon Sep 17 00:00:00 2001 From: Denys Vlasenko Date: Fri, 25 Sep 2009 01:50:45 +0200 Subject: login: log PAM errors to syslog, not stderr By Ian Wienand (ianw AT vmware.com) Signed-off-by: Denys Vlasenko --- loginutils/login.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) (limited to 'loginutils') diff --git a/loginutils/login.c b/loginutils/login.c index 31b25a43e..ed2ab7f80 100644 --- a/loginutils/login.c +++ b/loginutils/login.c @@ -409,7 +409,9 @@ int login_main(int argc UNUSED_PARAM, char **argv) break; /* success, continue login process */ pam_auth_failed: - bb_error_msg("pam_%s call failed: %s (%d)", failed_msg, + /* syslog, because we don't want potential attacker + * to know _why_ login failed */ + syslog(LOG_WARNING, "pam_%s call failed: %s (%d)", failed_msg, pam_strerror(pamh, pamret), pamret); safe_strncpy(username, "UNKNOWN", sizeof(username)); #else /* not PAM */ -- cgit v1.2.3