[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Full-disclosure] VNC viewers: Clipboard of host automatically sent to remote machine



> Guys, could you please read carefully everything before you reply?

I read carefully. It still didn't make sense, though.

> And you wouldn't be allowed to use copy&paste while you edit sensitive
> documents either, I guess?

I don't know how you could get to such a conclusion from what I wrote.

You're reporting that if you copy and paste sensitive information and
connect to a VNC session your clipboard data gets sent to the remote
machine. That's pretty obvious and not a security hole that needs to
be plugged.

On top of that, the attack scenario doesn't sound too good either. I
fail to see why would you need to copy&paste a password to access an
untrusted machine and then worry that machine might get to see the
password to itself. Also,most VNC servers store the password in clear
text in the configuration, and the entire protocol is in plain text,
for crying out loud.

A scenario where this could be a problem is so bizarre I sincerely
can't blame the developers for downright ignoring you. Instead of
crying wolf, it would have been much more sensible to go for a
no-nonsense approach and just ask the Vinagre developers to add the
same option every other VNC client has to disable the clipboard
sharing, just because it's a good option to have. My bet is they would
have listened.


-- 
“There's a reason we separate military and the police: one fights the
enemy of the state, the other serves and protects the people. When the
military becomes both, then the enemies of the state tend to become
the people.”

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/