magicJack and MagicJack Plus Support, Reviews, FAQs and Hacks Forum Index magicJack and MagicJack Plus Support, Reviews, FAQs and Hacks
magicJack and magicJack Plus Unofficial Technical Support. Your Magic Jack and Magic Jack Plus phone service information resource
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 
Potentially a MAJOR security hole in latest upgrade!

 
Post new topic   Reply to topic    magicJack and MagicJack Plus Support, Reviews, FAQs and Hacks Forum Index -> magicJack Tips, Tricks, and Hacks
View previous topic :: View next topic  
Author Message
j1sjeep
MagicJack User


Joined: 27 Jun 2008
Posts: 40

PostPosted: Mon Jun 15, 2009 9:53 pm    Post subject: Potentially a MAJOR security hole in latest upgrade! Reply with quote

So, I was perusing my dumpfile learning more about the upgrade. (Lots of clues in there BTW) When I stumbled upon my usernames and passwords a web-based utility I use at WORK and MY ONLINE BANKING information.

I'm certain that neither of these would be stored in a clear text manner anywhere on my system. I'm going to dig some more and make sure this info isn't stored in the clear. This could turn into a media worthy story... People need to know this.

So, boys and girls... Don't go posting dump files. And DO think about using your dongle on a dedicated PC\ThinClient\VM.
Back to top
View user's profile Send private message
Google
AdSense





PostPosted: Mon Jun 15, 2009 9:53 pm    Post subject: Magicjack support, tips, tricks, and hacks


Back to top
angel-78
magicJack Apprentice


Joined: 02 Jul 2008
Posts: 28
Location: SAN DIEGO

PostPosted: Mon Jun 15, 2009 10:13 pm    Post subject: Reply with quote

That has always been visible when you dump, its because more than just mj gets dumped. This is old news.
Back to top
View user's profile Send private message MSN Messenger
j1sjeep
MagicJack User


Joined: 27 Jun 2008
Posts: 40

PostPosted: Mon Jun 15, 2009 10:22 pm    Post subject: Reply with quote

I've never seen passwords for OTHER web services in dumpfiles before. MJ and pmdump are the only user processes that i ran... The PW's aren't in any cookies that I've found.

Domingo, thanks for the input... But not what I'm talking about. I'm saying in the MagicJack.exe memory space are uids and pws for other web based services. Part of the MJ plan was to deliver target advertising based on your browsing habits. They're collecting alot more than your browsing habits. They appear to be harvesting accounts for other services.

On your final note, check out the tigerjet hardware sdk...


Last edited by j1sjeep on Mon Jun 15, 2009 10:29 pm; edited 1 time in total
Back to top
View user's profile Send private message
angel-78
magicJack Apprentice


Joined: 02 Jul 2008
Posts: 28
Location: SAN DIEGO

PostPosted: Mon Jun 15, 2009 10:29 pm    Post subject: Reply with quote

Thanks for the bones Domingo, I figure its going to take me a little while to figure this out. I have been reading up on the certs and keys. I tried generating, but still no go. Thanks for your clues.

Manny
Back to top
View user's profile Send private message MSN Messenger
dan
Dan isn't smart enough to hire me


Joined: 12 Nov 2007
Posts: 113
Location: Denver

PostPosted: Mon Jun 15, 2009 10:44 pm    Post subject: Reply with quote

dont waste your time Certificates do not work for Authentication or anythibng else.. this is a farse not sure who started it but it has grown here like wildfire.. I chased this down for 1 day obtained the Certifcate it simply does not work!
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    magicJack and MagicJack Plus Support, Reviews, FAQs and Hacks Forum Index -> magicJack Tips, Tricks, and Hacks All times are GMT - 5 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



Powered by phpBB Turbo Extended Edition © 2010, phpBB Group