AnsweredAssumed Answered

How 's log from Splunk show credential

Question asked by Jay Phairintrapha on Aug 16, 2017

Have received a query from Splunk log owner advised that qualys scanner using clear text password

How can I check and start what to fix this issue

 

2017-08-09 19:01:45 10.38.46.53 GET /2015/sessions utf8=%E2%9C%93&session%5Busername%5D=test&session%5Bpassword%5D=test&session%5Bredirect_url%5D=http%3A%2F%2Fwww.qualys.com&commit=Sign+in 80 - 10.19.58.9 - - 403 4 5 0

2017-08-09 19:01:45 10.38.46.53 GET /2015/sessions utf8=%E2%9C%93&session%5Busername%5D=test&session%5Bpassword%5D=test&session%5Bredirect_url%5D=&commit=Sign+in 80 - 10.19.58.9 - - 403 4 5 0

 

10.19.58.9 is a qualys scanner

Outcomes