[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <CAJB2Jzu73+rrd3y1rE_8kK86x35kPMS1=twuppL9JD=2_gcsUQ@mail.gmail.com>
Date: Tue, 24 Jan 2012 18:07:45 +0100
From: Mario Vilas <mvilas@...il.com>
To: Ben Bucksch <news@...ksch.org>
Cc: full-disclosure@...ts.grok.org.uk
Subject: Re: VNC viewers: Clipboard of host automatically
sent to remote machine
On Tue, Jan 24, 2012 at 2:34 PM, Ben Bucksch <news@...ksch.org> wrote:
> Actual result:
> notepad.exe shows "My password"
> Expected result:
> Nothing.
No.
Expected result is to have the clipboard text sent to the remote
machine, if you have your client configured to do so. In a really
security sensitive environment you wouldn't be using the clipboard for
passwords anyway. Or you would disable clipboard sharing. Or you
wouldn't use a cleartext protocol to begin with.
You might as well report that if the user copies the password to the
clipboard at any other point during the session it also gets sent to
the server. I don't see why this should be the concern of the
developers of any VNC client.
--
“There's a reason we separate military and the police: one fights the
enemy of the state, the other serves and protects the people. When the
military becomes both, then the enemies of the state tend to become
the people.”
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists