[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Full-disclosure] VNC viewers: Clipboard of host automatically sent to remote machine



On Tue, Jan 24, 2012 at 2:34 PM, Ben Bucksch <news@xxxxxxxxxxx> wrote:
> Actual result:
> notepad.exe shows "My password"
> Expected result:
> Nothing.

No.

Expected result is to have the clipboard text sent to the remote
machine, if you have your client configured to do so. In a really
security sensitive environment you wouldn't be using the clipboard for
passwords anyway. Or you would disable clipboard sharing. Or you
wouldn't use a cleartext protocol to begin with.

You might as well report that if the user copies the password to the
clipboard at any other point during the session it also gets sent to
the server. I don't see why this should be the concern of the
developers of any VNC client.

-- 
“There's a reason we separate military and the police: one fights the
enemy of the state, the other serves and protects the people. When the
military becomes both, then the enemies of the state tend to become
the people.”

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/