[9276] in bugtraq

home help back first fref pref prev next nref lref last post

Windows CE 2.1 security problem

daemon@ATHENA.MIT.EDU (Bart)
Thu Jan 28 12:27:16 1999

Date: 	Wed, 27 Jan 1999 15:51:50 +0100
Reply-To: Bart <bart@MOEHA.NET>
From: Bart <bart@MOEHA.NET>
To: BUGTRAQ@NETSPACE.ORG

Hi,

Yesterday I discovered a security problem in Windows CE 2.1 for a
Palm PC (Cassiopeia E-11)

When you type text on the emulated keyboard, WinCE tries to guess the word
you're typing. When you enter a password (eg. for a dialup) WinCE will
consequently show the words which first characters match
your password's first characters.

The impact is quite obvious. When people can see your screen, they can see
a part of your password.

Kind regards,

Bart Van den Bossche

--
admin@turboline.net  http://www.moeha.net  bart@moeha.net
grep... grep... grep... (frog with unix stuck in his throat)

home help back first fref pref prev next nref lref last post