Notices

X5 Forums Talk about anything related to the X5.

Reply
 
LinkBack Thread Tools
Old 10-08-03, 02:19 PM   #1 (permalink)
Aximsite Prospect
 
Join Date: Oct 2003
Posts: 7
Thanked 0 Times in 0 Posts
Axim Password Brute Forcing

Hi Guys,

I'm new to the axim scene and I'll be deploying a bunch of these great PDAs to a group of users. I'm a little bit concerned about security and I've heard that the "power on" password can be bruteforced if the PPC is connected via active sync.

Some site mentioned certain manufacturers were taking steps to prevent this. Anyone know if Dell has beefed up the security at all?

Thanks!
scootss is offline   Reply With Quote
Sponsor Ads
Old 10-08-03, 02:47 PM   #2 (permalink)
Aximsite Major League
 
rai_dei's Avatar
Senior Member
 
Join Date: Jul 2003
Location: Torontonia
Posts: 472
Thanked 0 Times in 0 Posts
well, you can always do it the old fashioned way and do a hard reset, i think that resets the password.

As for bruteforcing, im not sure, seems a little farfetched.
__________________
Is there a porblem occifer?
rai_dei is offline   Reply With Quote
Old 10-08-03, 03:01 PM   #3 (permalink)
Aximsite Legend
 
Howard2k's Avatar
Addicted Member
 
Join Date: Jun 2003
Location: Toronto, Canada
Posts: 13,721
Thanked 4 Times in 4 Posts

Awards Showcase
Aximsite Active Silver Member Moderator Medal Silver Poster 
Total Awards: 3

Hard Reset also clears all the information that is not on Storage Card or Built In Storage. So limited value to get around the password :)

A 4 digit number password has 10,000 combinations.
A 10 digital alpha password has 144,555,105,949,057,024 combinations (depending of course on the character set support etc., but a good rough number). Good luck with that brute force attack :)
__________________
Always read stuff that will make you look good if you die in the middle of it.
Howard2k is offline   Reply With Quote
Old 10-08-03, 03:02 PM   #4 (permalink)
Aximsite Legend
 
Howard2k's Avatar
Addicted Member
 
Join Date: Jun 2003
Location: Toronto, Canada
Posts: 13,721
Thanked 4 Times in 4 Posts

Awards Showcase
Aximsite Active Silver Member Moderator Medal Silver Poster 
Total Awards: 3

There is also the time constraint. From the console the Axim will implement an increasing timeout between password guesses. Through AS I'm not sure if this still happens or not. But with a 20 digit alpha password I would let them go for their lives on a brute force.
__________________
Always read stuff that will make you look good if you die in the middle of it.
Howard2k is offline   Reply With Quote
Old 10-08-03, 04:54 PM   #5 (permalink)
Aximsite All Star
 
red-i's Avatar
Elite Member
 
Join Date: Jan 2003
Location: Toronto, Canada
Posts: 831
Thanked 0 Times in 0 Posts
at 1 try per second it would take at most 4 583 812 339 years!
That's with a 10digit alphanumeric as per howard's calculation of permutations.

Tell your group not to use built in storage or a storage card for sensitive data, that way as howard says, if it's hard reset, the data is gone (of course on that note make sure they backup frequently as well). Alternatively, you can use an encryption app to encrypt sensitive documents.
red-i is offline   Reply With Quote
Reply

Sponsor Ads

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 04:49 AM.
Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.3.0
Copyright © 2003-09 LeckMedia, LLC