lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Date: Tue, 24 Jan 2012 18:07:45 +0100 From: Mario Vilas <mvilas@...il.com> To: Ben Bucksch <news@...ksch.org> Cc: full-disclosure@...ts.grok.org.uk Subject: Re: VNC viewers: Clipboard of host automatically sent to remote machine On Tue, Jan 24, 2012 at 2:34 PM, Ben Bucksch <news@...ksch.org> wrote: > Actual result: > notepad.exe shows "My password" > Expected result: > Nothing. No. Expected result is to have the clipboard text sent to the remote machine, if you have your client configured to do so. In a really security sensitive environment you wouldn't be using the clipboard for passwords anyway. Or you would disable clipboard sharing. Or you wouldn't use a cleartext protocol to begin with. You might as well report that if the user copies the password to the clipboard at any other point during the session it also gets sent to the server. I don't see why this should be the concern of the developers of any VNC client. -- “There's a reason we separate military and the police: one fights the enemy of the state, the other serves and protects the people. When the military becomes both, then the enemies of the state tend to become the people.” _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists