So, I was perusing my dumpfile learning more about the upgrade. (Lots of clues in there BTW) When I stumbled upon my usernames and passwords a web-based utility I use at WORK and MY ONLINE BANKING information.
I'm certain that neither of these would be stored in a clear text manner anywhere on my system. I'm going to dig some more and make sure this info isn't stored in the clear. This could turn into a media worthy story... People need to know this.
So, boys and girls... Don't go posting dump files. And DO think about using your dongle on a dedicated PC\ThinClient\VM.
Potentially a MAJOR security hole in latest upgrade!
Moderators: Bill Smith, Pilot
I've never seen passwords for OTHER web services in dumpfiles before. MJ and pmdump are the only user processes that i ran... The PW's aren't in any cookies that I've found.
Domingo, thanks for the input... But not what I'm talking about. I'm saying in the MagicJack.exe memory space are uids and pws for other web based services. Part of the MJ plan was to deliver target advertising based on your browsing habits. They're collecting alot more than your browsing habits. They appear to be harvesting accounts for other services.
On your final note, check out the tigerjet hardware sdk...
Domingo, thanks for the input... But not what I'm talking about. I'm saying in the MagicJack.exe memory space are uids and pws for other web based services. Part of the MJ plan was to deliver target advertising based on your browsing habits. They're collecting alot more than your browsing habits. They appear to be harvesting accounts for other services.
On your final note, check out the tigerjet hardware sdk...
Last edited by j1sjeep on Mon Jun 15, 2009 11:29 pm, edited 1 time in total.