Geekzone: technology news, blogs, forums
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.
Security flaw in wireless client used in some Pocket PC devices identified
Posted on 17-Jan-2005 08:22. | Tags Filed under: News.

Security firm Airscanner has discovered a flaw in the way the Windows Mobile Odyssey client manages the WEP key information. The wireless driver included with the Dell X50 Pocket PC stores WEP keys as plaintext in the registry. The keys
KEY4=6677889900, KEY3=1122334455, KEY2=eeffddeeff, KEY1=aabbccddee are stored in the registry as


Airscanner says this could be a problem if the handheld is lost or borrowed. Since this information is stored as plaintext, anyone could read it and gain access to the WEP protected network registered with this device. This has not yet been tested with other devices that use the Odyssey client.

Originally the problem was thought to be within the Odyssey client used on these Pocket PC, but Funk Software, developers of the Odyssey client commented: "Odyssey encrypts all sensitive information that it stores in the registry. The example registry settings are not even from the area of the registry that Odyssey uses.

It is possible that the WEP keys you cite were stored by the NIC driver. An old practice, apparently not yet abandoned, is for NIC drivers to save the last configured WEP keys, so that they can be re-instantiated on reboot. Thus, when Odyssey sets the operational WEP keys for the adapter, the NIC driver might be storing them in its own area of the registry."

More information:

comments powered by Disqus

Trending now »

Hot discussions in our forums right now:

Street Harassment - I'm looking at you Max Key
Created by gzt, last reply by Geektastic on 29-Oct-2016 08:51 (86 replies)
Pages... 4 5 6

Gigabit cable now available
Created by sub, last reply by CableGuyChch on 29-Oct-2016 08:54 (268 replies)
Pages... 16 17 18

Parking Breach Notices
Created by cisconz, last reply by wasabi2k on 28-Oct-2016 15:28 (19 replies)
Pages... 2

RNZAF Boeing 757 breaks down when carrying PM. RNZAF must have an atrocious dispatch reliability figure.
Created by amiga500, last reply by frankv on 28-Oct-2016 13:21 (91 replies)
Pages... 5 6 7

The Quest for the Holy Grail - aka VDSL
Created by cynnicallemon, last reply by cynnicallemon on 28-Oct-2016 22:42 (17 replies)
Pages... 2

New MacBook Pro
Created by ajobbins, last reply by JoshWright on 28-Oct-2016 18:27 (17 replies)
Pages... 2

Is it me, or have Trade Me prices increased?!
Created by Geektastic, last reply by mattwnz on 27-Oct-2016 14:58 (32 replies)
Pages... 2 3

Disagreement with tradesman over invoice - escalation path
Created by timmmay, last reply by dejadeadnz on 28-Oct-2016 22:19 (31 replies)
Pages... 2 3