[GH-ISSUE #172] default Location of sqlite database reachable via http in some circumstances #111

Closed
opened 2026-02-28 01:21:02 +03:00 by kerem · 2 comments
Owner

Originally created by @margau on GitHub (Apr 17, 2018).
Original GitHub issue: https://github.com/tuxis-ie/nsedit/issues/172

Hello,
the default location of the userdb is ../etc/pdns.users.sqlite3

If you have installed nsedit in a directory (reachable via https://server/nsedit),
its possible to download the database trough https://server/etc/pdns.users.sqlite3.

Thats not extremly critical, because the passwords are hashed, but could be very bad.
A database is not something i would like to have available online to the public.

At least the user should be informed about this possibility to chose a proper, non-public available path.

Best regards
margau

Originally created by @margau on GitHub (Apr 17, 2018). Original GitHub issue: https://github.com/tuxis-ie/nsedit/issues/172 Hello, the default location of the userdb is ../etc/pdns.users.sqlite3 If you have installed nsedit in a directory (reachable via https://server/nsedit), its possible to download the database trough https://server/etc/pdns.users.sqlite3. Thats not extremly critical, because the passwords are hashed, but could be very bad. A database is not something i would like to have available online to the public. At least the user should be informed about this possibility to chose a proper, non-public available path. Best regards margau
kerem closed this issue 2026-02-28 01:21:03 +03:00
Author
Owner

@margau commented on GitHub (Apr 17, 2018):

See PR #173

<!-- gh-comment-id:382081452 --> @margau commented on GitHub (Apr 17, 2018): See PR #173
Author
Owner

@tuxis-ie commented on GitHub (Aug 22, 2018):

Closed via #182

<!-- gh-comment-id:415064645 --> @tuxis-ie commented on GitHub (Aug 22, 2018): Closed via #182
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/nsedit#111
No description provided.