mount.cifs: don't leak passwords with verbose option
authorJeff Layton <jlayton@redhat.com>
Fri, 25 Sep 2009 11:03:44 +0000 (07:03 -0400)
committerVolker Lendecke <vl@samba.org>
Fri, 22 Jan 2010 10:22:07 +0000 (11:22 +0100)
commit221c557f1fa0709cb5fc0c46ca5abcc480553a23
tree2ed3eb4a879c38f96d9fca8208617df72d08df78
parent4c58bbfd8488bfe88be8a304182c2e02b2f39dc1
mount.cifs: don't leak passwords with verbose option

When running mount.cifs with the --verbose option, it'll print out the
option string that it passes to the kernel...including the mount
password if there is one. Print a placeholder string instead to help
ensure that this info can't be used for nefarious purposes.

Also, the --verbose option printed the option string before it was
completely assembled anyway. This patch should also make sure that
the complete option string is printed out.

Finally, strndup passwords passed in on the command line to ensure that
they aren't shown by --verbose as well. Passwords used this way can
never be truly kept private from other users on the machine of course,
but it's simple enough to do it this way for completeness sake.

Reported-by: Ronald Volgers <r.c.volgers@student.utwente.nl>
Signed-off-by: Jeff Layton <jlayton@redhat.com>
Acked-by: Steve French <sfrench@us.ibm.com>
Signed-off-by: Christian Ambach <christian.ambach@de.ibm.com>
source/client/mount.cifs.c