Bugtraq mailing list archives

Hotline Client Plain password vuln.


From: "Rense Buijen" <Rense.Buijen () dct-mail com>
Date: Thu, 28 Feb 2002 09:33:51 +0100


Hello,

I am using Hotline Client 1.8.5 from Hotline Communications Ltd on a
windows XP platform. In this client you have the options to save
bookmarks so you can easily connect to your sites.  When I was looking
around in the "Bookmarks" dir (program files\hotline communications ltd)
I saw that the bookmarks store your login, password and host in
plaintext although it is a binary file. Has this been mentioned before?
Is this normal or just a flaw from the creators?

Cheers,

Rens 


Current thread: