Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    [BUG] System - Advanced - Miscellaneous shows admin credentials

    webGUI
    6
    9
    2.1k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • belleraB
      bellera
      last edited by

      With pfSense 2.2.5 64 bit (on pfSense SG-8860 hardware) I went to System - Advanced - Miscellaneous in order to activate the thermal sensors.

      My surprise is that a config.xml downloaded to my computer contains:

      <proxyuser>admin</proxyuser>
      <proxypass>mysecretpassword</proxypass>
      

      I suppose that the navigator (FireFox in my case) copied the latest fields introduced.

      It's a security problem. pfSense admin password can be easy copied and stored without encryption!

      I returned to the page an I entered

      not_used
      not_used

      And also edited my backup file to have also 'not_used' at the two fields…

      1 Reply Last reply Reply Quote 0
      • KOMK
        KOM
        last edited by

        That username and password are used to authenticate pfSense itself as a user on the upstream proxy you specify.  The whole Proxy Support section is to allow pfSense to access the Internet through a different proxy server.  It's not the pfSense Admin account.

        Edit: on second thought, are you saying that it prefills in this field with the real pfSense Admin account credentials?  Or is it just filling it with the default username & password of admin:pfsense?

        1 Reply Last reply Reply Quote 0
        • belleraB
          bellera
          last edited by

          Yes, I know.

          But my navigator auto-completed these fields without my intervention with my admin credentials.

          I didn't configured proxy access. I only went to activate the thermal sensors and [Save].

          1 Reply Last reply Reply Quote 0
          • D
            doktornotor Banned
            last edited by

            Yeah, so stop using your "navigator" that autofills in wrong fields without your intervention.  ::)

            https://doc.pfsense.org/index.php/Why_are_some_passwords_stored_in_plaintext_in_config.xml

            1 Reply Last reply Reply Quote 0
            • KOMK
              KOM
              last edited by

              Yes it appears to be a browser autocomplete issue.  When I changed my Admin password & told the browser to not update the password in its cache, and then saved my config and checked it, the proxypass was filled with the old password.

              1 Reply Last reply Reply Quote 0
              • D
                doktornotor Banned
                last edited by

                Yeah, the browsers are getting increasingly idiotic and it's more and more impossible to prevent them from using this "smart" autofill feature in completely wrong places.

                1 Reply Last reply Reply Quote 0
                • jimpJ
                  jimp Rebel Alliance Developer Netgate
                  last edited by

                  I'd love to stop that from happening but browsers simply ignore any HTML directive to disallow autofill. They think they know better and want to fill in all the fields they believe are passwords. We've tried a few tricks to stop it from happening but nothing sane seems to work. Even if the form field names are randomized if the labels contain things that might be credentials they still auto-fill.

                  Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                  Need help fast? Netgate Global Support!

                  Do not Chat/PM for help!

                  1 Reply Last reply Reply Quote 0
                  • RonpfSR
                    RonpfS
                    last edited by

                    I changed the admin password a few times this morning, pfsense 2.2.5 x32 using Firefox 42.0

                    with WebGUI Login Autocomplete ticked and not ticked, toggle the PowerD setting, save,
                    save the config and the proxypass never changed, always the defaut : "pfsense"

                    2.4.5-RELEASE-p1 (amd64)
                    Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                    Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                    1 Reply Last reply Reply Quote 0
                    • C
                      cmb
                      last edited by

                      The admin password is unrelated to the proxy password. Your browser auto-filled it if it's set there, just clear it and make sure it remains that way if you save further changes on the page.

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.