Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Sharp Zaurus Predictable Salt Password Weakening Vulnerability

Zaurus is a handheld device distributed by Sharp Electronics.

By default, the Zaurus encrypts the screen lock password using the salt 'A0'. An attacker with knowledge of the password hash can use the salt to create a map of passwords. From this map, an attacker would be able to look up the hash to recover a password.







 

Privacy Statement
Copyright 2009, SecurityFocus