2014-11-27 @ 19:25: How to recover saved passwords from Gnome Connection Manager BugsSecurity

About two weeks ago I found a bug in Gnome Connection Manager 1.1.0 which allows you to recover saved passwords (e.g. in case you forgot them). To my mind this bug is kinda harmless as long as no one gains access to your gcm.conf file. I informed Renzo Bertuzzi, the author of GCM, and he immediately came up with a fix. Thanks for that! However, since no update is available, yet, I will disclose this bug to the public.

  • Use GCM to connect to any server with saved credentials
  • Open a text file using “less” and search for any string (maybe this is optional, I didn’t check)
  • Press Ctrl+N repeatedly (3x works for me) until you get kicked out of less (may take some seconds) and the password will be shown

The Ctrl+N key is the default for reconnecting to the server. So, in case you changed it, press the respective shortcut.

Comments Off on How to recover saved passwords from Gnome Connection Manager


  • About

    We never asked for this.