Re: Network Workgroup File - Password in the "Clear"? -
07-13-2010
, 03:05 AM
To the best of my knowledge it is not directly sniffable. I cannot
remember what crypto scheme it uses to encrypt the plaintext, but it
might be possible to identify the type of transmission (ie/ network
block type) with wireshark when the application is started, then
subsequently identify the actual comparison / lookup, then decrypt it.
In short it is probably do-able, I am just not sure that it is worth
the effort when you could probably just attack the workgroup file
directly, or the BE directly depending on your intent.
If security is a serious issue for you then you may want to consider a
product with a more capable and integrated security system. There are
plenty of good server type databases available on the market for free,
with good security models, and will still allow you to keep the FE you
have created in Access. Just a thought.
Cheers
The Frog |