Unsecure passwords in Macromedia Dreamweaver

From: Jeff Forristal (jeffat_private)
Date: Thu Jun 11 1998 - 11:04:34 PDT

  • Next message: Tom Perrine: "Solaris 2.5.1 patch not effective?"

    When one saves their ftp passwords in Macromedia Dreamweaver, this
    information is written to the registry at
    /HKEY_CURRENT_USER/Software/Macromedia/Dreamweaver/Sites/-Site(x)/User PW
    The storage scheme used to crypt the password is exactly the same as the
    Ws_FTP method, which was reported previously.  Briefly, all characters are
    converted to hex, and the offset within the string is added to the value
    (starting with 0).
    
    Macromedia has been contacted, and their reply was to the effect that,
    while noted, they do not think it severe enough to release a patch;
    therefore, it will be corrected in the next major release.
    
    -Jeff Forristal
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 13:57:12 PDT