Host-based backup of VMware vSphere VMs.
Post Reply
lucaliga
Influencer
Posts: 15
Liked: 6 times
Joined: Jan 11, 2016 8:37 am
Contact:

SureBackup Session Reports - Microsoft SQL Server Checker script privacy issue

Post by lucaliga »

Hello,

We start using SureBackup in our Veeam Backup & Replication 9.5.0.1922. We get surprised looking at the SureBackup Session Reports received by email. For VMs having Microsoft SQL Server Checker script enabled with SQL Server authentication mode then the passed credentials of the account as arguments to the script are available in the report section "Custom script test" in clear text (here I replaced both with fake):

Sql Checker (SQL authentication) script, Path: c:\Program Files\Veeam\Backup and Replication\Backup\Veeam.Backup.SqlChecker.vbs, Args: C:\ProgramData\Veeam\Backup\SureBackup_Job_Main 192.168.255.17 <dbadmin> <securepassword>, Result: Passed

Seems to me a privacy and security issue. There is a way to obscure/remove detailed "Args" reported in the "Custom script test" section of report ?

Thanks
Regards
Luca
foggy
Veeam Software
Posts: 21071
Liked: 2115 times
Joined: Jul 11, 2011 10:22 am
Full Name: Alexander Fogelson
Contact:

Re: SureBackup Session Reports - Microsoft SQL Server Checker script privacy issue

Post by foggy »

Hi Luca, thanks for the heads up! Looks scary, indeed. I will check with the team on Monday.
foggy
Veeam Software
Posts: 21071
Liked: 2115 times
Joined: Jul 11, 2011 10:22 am
Full Name: Alexander Fogelson
Contact:

Re: SureBackup Session Reports - Microsoft SQL Server Checker script privacy issue

Post by foggy »

Seems like it is the way that it is. However, there's a workaround - if you call the script with arguments from a cmd file (instead of calling .vbs directly and specifying credentials in UI), then only cmd file name will be logged.
Post Reply

Who is online

Users browsing this forum: No registered users and 80 guests