One of the difficulties with spy tool applications is that even if they are legitimately used – the application vendor still has the problem of properly handling confidential data.

Case in point: Mobile-Spy for Windows Mobile.

Until recently (the last 48 hours or so) they had an issue with their web interface. The issue potentially allowed access to any communication data collected by their software.

Now that they've resolved the issue, we'll explain…

By using their Demo account to log onto their system, you were only supposed to be able to access demo messages. The logon is found at the following URL:

Smart Demo
This URL is from one of the demo messages that you're supposed to be able to view. Notice that the message ID is plainly visible in the URL. So, what happened if you changed the ID number in the URL?

Demo URL

We used 34841 as an example:

Test URL

Last week the result of adjusting the URL was this:

Before

And now the result is this:

After

So, Mobile Spy has corrected the potential problem. You can read more details from ZDNet.

Posted by Jarno @ 12:22 GMT
http://www.f-secure.com/weblog/archives/00001285.html
arrow
arrow
    全站熱搜
    創作者介紹
    創作者 ivan0914 的頭像
    ivan0914

    I'n Blog 之萬象真藏

    ivan0914 發表在 痞客邦 留言(0) 人氣()