bugtraq
[Top] [All Lists]

Re: SYMSA-2007-002: Palm OS Treo Find Feature System Password Bypass

To: bugtraq@securityfocus.com
Subject: Re: SYMSA-2007-002: Palm OS Treo Find Feature System Password Bypass
From: agonline.dummy@gmail.com
Date: 16 Feb 2007 16:56:40 -0000
Delivered-to: sp-com-lists@consult.net
Delivered-to: bugtraq-list@securepoint.com
Delivered-to: mailing list bugtraq@securityfocus.com
Delivered-to: moderator for bugtraq@securityfocus.com
List-help: <mailto:bugtraq-help@securityfocus.com>
List-id: <bugtraq.list-id.securityfocus.com>
List-post: <mailto:bugtraq@securityfocus.com>
List-subscribe: <mailto:bugtraq-subscribe@securityfocus.com>
List-unsubscribe: <mailto:bugtraq-unsubscribe@securityfocus.com>
Mailing-list: contact bugtraq-help@securityfocus.com; run by ezmlm
All this hype over Treo's bug using 'Find' feature is unnecessary. This is 
completely false that hacker can get access to data. I tested it myself on my 
treo 650 and found out that I can only see the results after executing Find 
function. As soon as I click on any one of the find results, treo takes me back 
to the phone screen and does not let me enter into any of the contacts, memos, 
calendar or anything.

The agencies reporting the bug are not giving complete information. They told 
that hacker can access the Find functiona and see the results. But they did not 
tell that hacker CANNOT access any treo entry by clicking on the find results.

<Prev in Thread] Current Thread [Next in Thread>