Bugtraq mailing list archives

Windows CE 2.1 security problem


From: bart () MOEHA NET (Bart)
Date: Wed, 27 Jan 1999 15:51:50 +0100


Hi,

Yesterday I discovered a security problem in Windows CE 2.1 for a
Palm PC (Cassiopeia E-11)

When you type text on the emulated keyboard, WinCE tries to guess the word
you're typing. When you enter a password (eg. for a dialup) WinCE will
consequently show the words which first characters match
your password's first characters.

The impact is quite obvious. When people can see your screen, they can see
a part of your password.

Kind regards,

Bart Van den Bossche

--
admin () turboline net  http://www.moeha.net  bart () moeha net
grep... grep... grep... (frog with unix stuck in his throat)



Current thread: