On Tue, Jan 24, 2012 at 2:34 PM, Ben Bucksch <[email protected]> wrote: > Actual result: > notepad.exe shows "My password" > Expected result: > Nothing.
No. Expected result is to have the clipboard text sent to the remote machine, if you have your client configured to do so. In a really security sensitive environment you wouldn't be using the clipboard for passwords anyway. Or you would disable clipboard sharing. Or you wouldn't use a cleartext protocol to begin with. You might as well report that if the user copies the password to the clipboard at any other point during the session it also gets sent to the server. I don't see why this should be the concern of the developers of any VNC client. -- “There's a reason we separate military and the police: one fights the enemy of the state, the other serves and protects the people. When the military becomes both, then the enemies of the state tend to become the people.” _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
