[9276] in bugtraq
Windows CE 2.1 security problem
daemon@ATHENA.MIT.EDU (Bart)
Thu Jan 28 12:27:16 1999
Date: Wed, 27 Jan 1999 15:51:50 +0100
Reply-To: Bart <bart@MOEHA.NET>
From: Bart <bart@MOEHA.NET>
To: BUGTRAQ@NETSPACE.ORG
Hi,
Yesterday I discovered a security problem in Windows CE 2.1 for a
Palm PC (Cassiopeia E-11)
When you type text on the emulated keyboard, WinCE tries to guess the word
you're typing. When you enter a password (eg. for a dialup) WinCE will
consequently show the words which first characters match
your password's first characters.
The impact is quite obvious. When people can see your screen, they can see
a part of your password.
Kind regards,
Bart Van den Bossche
--
admin@turboline.net http://www.moeha.net bart@moeha.net
grep... grep... grep... (frog with unix stuck in his throat)