Join | Sign in to Windows Live ID
in Search
LIKE WHAT YOU SEE? CLICK JOIN ABOVE TO SIGN UP, POST, AND ATTEND LIVE EVENTS.

ActiveSync 4.x and Windows XP Security Exploit

Last post 10-02-2008 9:16 AM by Bill Fisher. 0 replies.
Page 1 of 1 (1 items)
Sort Posts: Previous Next
  • 10-02-2008 9:16 AM

    • Bill Fisher
    • Top 10 Contributor
    • Joined on 03-20-2008
    • Portland, OR
    • Posts 766
    • Points 9,961
    • 2_advocate
      SystemAdministrator

    ActiveSync 4.x and Windows XP Security Exploit

    I'm no security expert, but a number of blogs are reporting on a recent security warning about ActiveSync 4.x and Windows XP machines. The gist of the issue, according to the security researcher who found the problem:

    "... a hacker can walk up to a Windows XP PC with ActiveSync 4.x installed, plug in a Windows Mobile device, and have direct TCP/IP access to the computer. This works even if the computer is locked or logged out.

     Such attacks are possible because of a communication component called RNDIS (remote network driver interface specification), introduced with ActiveSync 4.x... The RNDIS component gives ActiveSync the ability to transfer its syncing related data via IP packets within the USB connection...

    The problem is that in order for the ActiveSync operation to perform authentication of the session, the RNDIS connection must first establish an IP connection. Once the IP addresses are assigned and TCP/IP data can flow, the syncing process starts. In other words, a Windows Mobile device connected to a system with ActiveSync 4.x running will have direct TCP/IP access through an uncontrolled and unprotected network interface."

     What do you more security-savvy members think of this? 

    • Post Points: 5
Page 1 of 1 (1 items)
  * WANT TO LET SOMEONE KNOW ABOUT THE CONNECTION? SEND AN INVITATION! *