Re: ActiveSync can access a locked workstation w/o unlocking

From: Melody Yoon - KF6RMW (melodyyat_private)
Date: Mon Apr 16 2001 - 13:51:35 PDT

  • Next message: Franklin DeMatto: "qDefense Advisory: DCForum allows remote read/write/execute"

    Actually, did you attempt to do this with a device that doesn't have a
    partnership with the desktop computer already? I just attempted to try to
    sync with my ipaq using active sync with the cradle and activesync
    attached, but did not do anything else since the screen "do you want to
    set up a partnership" was shown on the screen once I unlocked. No data
    access was possible.
    
    I think this in itself is not a direct security issue unless the WinCE
    device was stolen, or whathaveyou. My understanding of why activesync
    works with this behavior is to also allow network synchronization while
    the workstation is locked.
    
    Mel
    
    (I've included the original email for clarity reasons)
    
    On Mon, 16 Apr 2001, Jeff.Samples wrote:
    
    > Microsoft was notified on 3/28/2001, you may use my name when publishing
    > this. I cannot register on your site, so I am trying the general e-mail
    > addresses.
    >
    > Platforms tested:
    > ===================================================
    > Microsoft Windows 2000 Professional (build 2195) w/ SP1
    > Microsoft ActiveSync 3.1 (tested using HP Jornada 540 Series running Windows
    > PocketPC (CE v 3.0.948 Build 9357)
    >
    > Issue:
    > ===================================================
    > MS ActiveSync can access files (Outlook appts, contacts, synced files, etc)
    > from a Win2K workstation even though the workstation has been locked.  By
    > simply dropping the HP into the dock, or hooking it up to the COM
    > port(depending on which sync method is configured), it will sync and
    > download data from a "locked" workstation. Yikes!
    
    Melody Lynn Yoon      melodyy+KF6RMWat_private                 |Graduate '97 MSF
    Unix Systems Administrator - MSN Hotmail - melodyat_private |NRA Member
    California OES CERT Member and American Red Cross Emergency Communication Team
    
    - I do not accept commercial, unsolicited email | kf6rmw@w6yx.#nca.ca.usa.noam
    - http://www.best.com/~melodyy/spam.policy.html | KF6RMW - Amateur Radio
    



    This archive was generated by hypermail 2b30 : Tue Apr 17 2001 - 00:57:56 PDT