Re: Microsoft DevDays 2004 - Smart Client - security demo question

From: Nicole Calinoiu (calinoiu)
Date: 01/19/05


Date: Wed, 19 Jan 2005 08:43:18 -0500

Which slide number?

"one" <one@discussions.microsoft.com> wrote in message
news:188B8791-9703-4562-91E4-B167D1839809@microsoft.com...
> Hi there,
>
> Have you guys watched the Smart Client 3: Developing Secure Smart Client
> Applications by a presenter called Jeff Levinson
> (http://msdn.microsoft.com/events/devdays/sessions/).
> I have got a really really quick question regarding the security hole he
> found on the demo...
>
> (you need to have watched it to understand the following)
> He said he decrypted his credential on the database server and upload his
> database connection string in clear text?? And then he can patcket sniff
> all
> the traffic in between teh application server and the database server...
> (Sorry, I may have heard it incorrectly as I was watching the webcast on
> the
> net and English is not my mother tongue.)
>
> Can someone explain to me a little more on what exactly did he mean.
>
> Thanks heaps!!



Relevant Pages

  • Microsoft DevDays 2004 - Smart Client - security demo question
    ... Have you guys watched the Smart Client 3: ... Applications by a presenter called Jeff Levinson ... He said he decrypted his credential on the database server and upload his ...
    (microsoft.public.dotnet.security)
  • Microsoft DevDays 2004 - Smart Client 3 - Security session
    ... Have you guys watched the Smart Client 3: ... Applications by a presenter called Jeff Levinson ... He said he decrypted his credential on the database server and upload his ...
    (microsoft.public.sqlserver.security)
  • Re: Microsoft DevDays 2004 - Smart Client 3 - Security session
    ... probably talking about using IPSEC between the app server and database ... > Have you guys watched the Smart Client 3: ... > He said he decrypted his credential on the database server and upload his ...
    (microsoft.public.sqlserver.security)
  • Create SharePoint Portal failed.
    ... One mentioned ensuring that SQL Server uses a case ... 13:55:40 Service database server is 'USDC-JOHRIV'. ... Update dbo.propertylist set DisplayName = N'Last name' ...
    (microsoft.public.sharepoint.portalserver)
  • Re: ADO Connection Timeout
    ... to the central server, but you are willing to live with periods where it ... i.e. a local database or even a text file. ... to function until the connection can be restored to the server. ...
    (microsoft.public.data.ado)