Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

跨机器复制.wind文件夹后,应该在WindTerm.exe启动后打开Sessions前再次让用户输入密码,不然没有安全性可言。木马程序可以随便搜索并复制走用户机器上的.wind夹所有Sessions并随意连接。 #2432

Open
chinapsu opened this issue Jul 1, 2024 · 0 comments

Comments

@chinapsu
Copy link

chinapsu commented Jul 1, 2024

跨机器复制.wind文件夹后,应该在WindTerm.exe启动后打开Sessions前再次让用户输入密码,不然没有安全性可言。木马程序可以随便搜索并复制走用户机器上的.wind夹所有Sessions并随意连接。

建议 参考XShell那样,跨机器时重新让用户输入密码进行验证。也就是说,.wind中的Sessions密码加密算法要结合主板、机器名等硬件信息做加密,更换机器后保障原加密的密码失效,保障用户会话安全。

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant