kripod / kripod/MoneroGui.Net

Password security threat - easy to steal

Open
#20 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
C#
Stars
18
Forks
15
PR merge metrics
No merged PRs in 30d

Description

Process Explorer can be used to view the password. This mean anybody can view the password like trojans built for it (maybe I should build one :)). There is a way to run console apps in pipeline without command line / subprocess (maybe I'm wrong, but I think there is a way to supply args via stream)

see pictures attached

![simplewallet subprocess2](https://cloud.githubusercontent.com/assets/2981715/12214134/5776b004-b64e-11e5-8d16-def7617aae8f.png)
![simplewallet subprocess](https://cloud.githubusercontent.com/assets/2981715/12214133/57762a12-b64e-11e5-8179-4985e79d57ea.png)

Contributor guide

No contributing guide indexed for this repository

Research direction

No source file, test, or concrete entry point is named. Start by tracing how the GUI supplies the password to the console app and subprocess, then verify with Process Explorer that the password is no longer exposed; completion should address the reported password-visibility threat.

Written by the indexing model from the issue text.

Assessment

Tech stack
csharp
Domain
desktop, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.