consulting

User passwords exposed by Splunk
PDF Print E-mail
Written by Terence Sequeira
Tuesday, 11 May 2010 05:30

Splunk has 1,750 customers including BT, Cisco, LikedIn, Nasa, Visa and the US Department of Energy. 
Its software is downloaded from the web and is used as a search, monitor and reporting tool that crawls through the raw data on applications, hardware 
and network systems.

The passwords of customers on Splunk.com were revealed after some debug information leaked on to its production servers. 
The debug code exposed users passwords to Splunk.com as clear text!!

Splunk has reset all affected users passwords.

The interesting part is a survey of web users' habits in the UK alone in January found 46 per cent use the same password for most web-based accounts.

Ref:http://www.theregister.co.uk/2010/04/26/splunk_passwords_revealed/