lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <CAJB2JztX637DCQXxdQE-DHPqwF5bem75Dtwy63vjdRup45_N=g@mail.gmail.com>
Date: Tue, 24 Jan 2012 19:18:08 +0100
From: Mario Vilas <mvilas@...il.com>
To: Ben Bucksch <news@...ksch.org>
Cc: full-disclosure@...ts.grok.org.uk
Subject: Re: VNC viewers: Clipboard of host automatically
 sent to remote machine

> Guys, could you please read carefully everything before you reply?

I read carefully. It still didn't make sense, though.

> And you wouldn't be allowed to use copy&paste while you edit sensitive
> documents either, I guess?

I don't know how you could get to such a conclusion from what I wrote.

You're reporting that if you copy and paste sensitive information and
connect to a VNC session your clipboard data gets sent to the remote
machine. That's pretty obvious and not a security hole that needs to
be plugged.

On top of that, the attack scenario doesn't sound too good either. I
fail to see why would you need to copy&paste a password to access an
untrusted machine and then worry that machine might get to see the
password to itself. Also,most VNC servers store the password in clear
text in the configuration, and the entire protocol is in plain text,
for crying out loud.

A scenario where this could be a problem is so bizarre I sincerely
can't blame the developers for downright ignoring you. Instead of
crying wolf, it would have been much more sensible to go for a
no-nonsense approach and just ask the Vinagre developers to add the
same option every other VNC client has to disable the clipboard
sharing, just because it's a good option to have. My bet is they would
have listened.


-- 
“There's a reason we separate military and the police: one fights the
enemy of the state, the other serves and protects the people. When the
military becomes both, then the enemies of the state tend to become
the people.”

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ