OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: FW:PcAnywhere weak password encryption
From: Dug Song (dugsongMONKEY.ORG)
Date: Wed Apr 12 2000 - 12:14:26 CDT


On Wed, 12 Apr 2000, Steve Topilnycky wrote:

> Title: 'Protecting pcAnywhere Logins and Passwords'
> http://service1.symantec.com/SUPPORT/pca.nsf/docid/1999031209465812&src=w

 "pcAnywhere takes steps to prevent exposing the login and password
  while establishing a remote session by transmitting this information
  using whichever encryption level has been selected. However, if
  encryption is turned off, that information is passed in the clear.
  For this reason, the default encryption level is pcAnywhere encryption."

fwiw, dsniff now handles both cases - cleartext, and pcAnywhere-encrypted.

           http://www.monkey.org/~dugsong/dsniff/

-d.

---
http://www.monkey.org/~dugsong/

_____________________________________________________________________ ** TO UNSUBSCRIBE, send the command "UNSUBSCRIBE win2ksecadvice" ** FOR A WEEKLY DIGEST, send the command "SET win2ksecadvice DIGEST" SEND ALL COMMANDS TO: listservlistserv.ntsecurity.net