mailing list archives
Re: Putty Proxy login/password discolsure....
From: "Dave \"No, not that one\" Korn" <davek_throwaway () hotmail com>
Date: Wed, 25 Oct 2006 14:52:37 +0100
"Antoine SANTO" <Antoine.SANTO () maaf fr> wrote in message
news:021001c6f822$94e12f40$595ce60a () maafprod ecorail com
I come to report a little strange discolsure discovered by my
When you save session informations under putty and you need proxy
for a session,
We can find in plain clear text the login and password proxy auth in
Strange to see a good ssh client storing plain clear text « hot »
The HKCU key is protected by an ACL; it is only accessible to the
user, or to someone with admin rights. So it's not best practice,
agreed, but it isn't a major vulnerability.
Can't think of a witty .sigline today....
Full-Disclosure - We believe in it.
Hosted and sponsored by Secunia - http://secunia.com/
Re: Putty Proxy login/password discolsure.... mflaschen3 (Oct 25)