Vulnerability Development mailing list archives

Reachout 8.4x


From: chris () AMGROUPADMIN COM (Chris Smith)
Date: Mon, 10 Apr 2000 23:24:21 -0000


Does anyone know of any vulnerabilities with Stac's
Reachout 8.4x for Win9x/NT?  I can't seem to find any
information either way about it anywhere.  I am referring
to the recent issues with PCAnywhere 9 and Netopia's
Timbuktu Pro sending either completely cleartext or weakly
encrypted usernames and password using a simple
mathematical formula to en/decrypt.  I am wondering if
Reachout is no better?  Additionally, the companies'
lackadasical attitude towards these glaring security holes
is quite disturbing.  According to the person who
discovered' Timbuktu's problem, Netopia's response to
sending cleartext passwords over internet connections was
complete indifference.

Perhaps this program needs to be researched.
Unfortunately, I lack the skill and time to effectively
research this problem.

Thank you

Chris Smith


Current thread: