Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

Re: Logitech Keyboard Insecurity
From: Paul Cardon <paul () moquijo com>
Date: Thu, 02 May 2002 18:15:54 -0400

keyboardhacker () hotmail com wrote:
 Logitech has been contacted about 1 month ago and they have
confirmed it is indeed a problem with their software, but a
fix is not yet out. A 'locked' computer should indeed be
locked, and not accessible via any means. While this bug is
a low risk, it shows how *obvious* flaws go undetected. It
totally bypasses GINA (Graphical Identification aNd
Authentication), which is supposed to keep the PC secure (to
the extend of requireing Ctrl-Alt-Delete to login).


Hrrm... Is the driver signed by Microsoft? If it is, that seems to be something that Microsoft should be checking from now on before they certify keyboard drivers.

-paul



  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]