« Widget Watch: EasyEnvelopes 1.1 | Main | Hurricane Wilma beats our ass... »

Avoid using customized Virex eUpdate settings

[ via MacOSXhints.com ]

virexAs you probably know, Apple has dropped support for Virex in .Mac, but there are still some people using it. Both Virex 7.2 and 7.5 give you the option to customize you eUpdate settings -- the goal of this is to prevent you from having to type in your .Mac password all the time in certain cases. For example, if you are updating Virex but don't have your .Mac account configured. That basically means that the following does not affect all users -- just the users who have set their username and password in the custom eUpdate settings.

Should you choose to customize you eUpdate settings, Virex does something pretty insecure. Instead of storing your username and password in the Keychain (a task that takes less than 100 lines of code to accomplish for store, retrieve, and update), they store it in a file. In the case of Virex 7.2, the file is stored in your user's ~/Library -> Preferences folder, in a file named VirexPrefs.vprF ... with the password and username in plain text!


In the case of Virex 7.5.1, the file is stored in /Library --> Preferences -> com.nai.virex75.prefs.plist with the username as plain text while the password is hashed. Note, though, that all users have access to this file, and while I am not sure how good the hash is, I do know that by simply copying the file to a second machine, you can have access to Virex updates from that second machine -- something that all users can do because all users have read access to the file. This kind of careless disregard for the protection of a .Mac user's credentials -- hashed or not -- is inexcusable.


If you're a Virex user, please check for the above-listed files and delete them if you find your .Mac info in them. And to prevent their creation in the future, don't customize your eUpdate settings!

Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)


Please enter the security code you see here

January 2007

Sun Mon Tue Wed Thu Fri Sat
  1 2 3 4 5 6
7 8 9 10 11 12 13
14 15 16 17 18 19 20
21 22 23 24 25 26 27
28 29 30 31      

dreamhost



Technorati


Add to Technorati Favorites

Get LinkedIn!

View Frank Bisono's profile on LinkedIn

Archives

Creative Commons License

This weblog is licensed under a Creative Commons License.

Linkage








© 2006 : Frank Bisono
::: Bisonium.com :::