Still can't paste into password fields in WM5 - Windows Mobile Development and Hacking General

Hi mates,
When I first got me PDA2k I was pretty dissapointed that I wasn't able to paste copied passwords into password fields of system applications as well on pocket IE websites.
Just a few days ago I got PDA Universal and was very unhappy to realize I can't do that still.
Is there any hack/fix to help with this problem?
Thank you.

It's is actually not meant to be possible. Copying and pasting a password means that you risk that someone recalls the last entry in your clipboard buffer, and discovers your password.

So Microsoft is again thinking for me. Thanks, but I can clean my buffer with copying couple of spaces afterwards in this case.
Anyone has tried to hack this restriction?

Related

Password locked phone: anyway to hack and access data?

Guys,
My wife put in a password to lock her phone (sensitive data) and now she doesn't know what it is, is there a way that I can dump the contents or access the data on the device? She took client notes on it and they were not set to be sync'd with her desktop, she needs them desperately. I'm the one that set up the syncing for NOTES and not WORD docs so I'm in deep S&*t with her!
The docs are in 'my documents' on the phone and not on the SD card.
Anyone able to do it?
Is there a limit on the number of try's?
When using a remote viewing/control software could I simple write a program that continues to run through the 9999 combos or the x trillion combos if she used the alpha-num setting? Are you able to enter the password on the desktop machine?
I like my private parts, please help!
I know a hardreset will dump everything on the phone and then she would be able to use the phone but I'll still be missing a couple of valuable parts of my body, if you know what I mean!!!!!!!!!!!!!!
Try to get your wife to remember at least the first number, so that you only have 999 tries before you actually find the correct code.
I didn't think it was to much to ask her to reminber the other 3 also but as wives will do, its still my fault for not backing it up!
Don't know anything that might help right now, but if I find something, I'll let you know. Also, for information, you might want to try SignWise - it uses a signature as a 'password' - and it's quite good
if my memory is correct (which isn't always the case) there is a program that shows your xda screen on the pc and you can manipulate it there. This in cooperation with a macro/keyrecorder you might get thru it. It probably would still need a lot of editing of the macro.
Thanks guys,
dcs, but then I won't be able to check on her
Does anyone know how to hack this?
Im stuck too. I thought maybe downloading the rom to the SD card might work, but you would have to do hard reset which would lost the data.
You might be able to try setting the active synch to backup up word documents (do it from the pc) then put the XDA in the cradle. Then try to forcefully synch from the PC. It might bypass the password.
I may have a solution, give me a couple of days to try it out and I'll let you know. In the meantime dont hard
reset orplay with it.
Cradeling the device requires the password before the connection is completed so I can't explore the device.
it's not an xda then i suppose ?
because all the xda's i've had synch without the password unless you are forming a new pathership
Its an MDAIII, but I think it still works the same with the WM2003 XDA. Maybe the solution in an old active sync, but I don't think I can go back in a version because the device is updated when I went to 3.7
Can anyone confirm if you can access data when a password is set using an old active sync?
well i can confirm that when i once types in the password for a connection and make it save it then i'm never required to type in the password again when i sync
If I had the Password the first time she entered it we could have done that but she forgot it before it was ever sync'd with the computer. So I need the password for the first time.
Anyone ever use this?
pget.exe gets files from your PocketPC.
http://wiki.xda-developers.com/wiki/XdaUtils
pget.exe Doesn't work until the password is entered to establish the link, it just sits there waiting for a connection. As soon as the Password is entered, it dumped the files to the PC (testing on my phone)
You may patch Active Sync so that it would not stop asking you a password after 3 wrong attempts:
old wcescomm.exe - patched WCESCOMM.EXE
00006C26: 74 90
00006C27: 05 90
Then you can "guess" the password by a bruteforce.
This patch is for ActiveSync 3.7.1 build 4034
You should kill WCESCOMM.EXE process before patching.

Anyone using SplashID on their K-Jam?

I'm trying to get my database moved to my K-Jam from my PDA2K. I can't seem to make it work. I move the .sdb, but it won't open on my K-Jam. Not sure if I'm missing something.
Thanks,
tom
twn2 said:
I'm trying to get my database moved to my K-Jam from my PDA2K. I can't seem to make it work. I move the .sdb, but it won't open on my K-Jam. Not sure if I'm missing something.
Thanks,
tom
Click to expand...
Click to collapse
This is what works for me: From the desktop SplashID app, "Export" all items in the PDA2K database to a .vid file, install SplashID on the KJAM setting the password to the same one as the desktop SplashID app and then sync. This will establish a new SplashID user (with blank data) in the desktop app with the same user name as the KJAM device name. Set the password for this new user to the same as on the KJAM SplashID. "Import" the saved database .vid file to the new user on the desktop. Make sure that SplashID is checked in the ActiveSync options and then re-sync. After that all the PDA2K data will be on your KJAM.
Frank
So there's not a way to just copy the database (or beam it) to my K-Jam?
Tom
Here's the strange part, I tried your suggestion but ran into a problem. I got the files into the SID desktop, but when I try to sync, it says the passwords don't match and it won't transfer. It takes the same password to open the desktop as it does to open the pda. Not sure what's wrong.
I keep getting "67 items unresolved" and password must match in order to sync. They do match though!
Thanks,
Tom
I don't know. This always works for me. I guess I would try uninstalling SID on the KJAM and then reinstalling it, making sure that the pw matches the desktop SID pw and then re-syncing. Seems like something is wrong with your pw somewhere so just redefining it to a simple one like "1234" on both SIDs and then syncing might be the first thing to try.
The problem that I used to have before using the procedure that I outlined before was that I would get duplicates of both the data items and the categories so I would sometimes wind up deleting all data and categories from both the desktop and PDA SIDs, then importing the data to the desktop SID from the .vid file and re-syncing. This would clear things up.
Sorry I am not more help here,
Frank
No problem....thanks for the suggestions. I just tried deleting everything I could find relating to SID and started over. No luck...password problem still. I've sent an email over to SplashData for help. Thanks again!!
Tom
twn2 said:
Here's the strange part, I tried your suggestion but ran into a problem. I got the files into the SID desktop, but when I try to sync, it says the passwords don't match and it won't transfer. It takes the same password to open the desktop as it does to open the pda. Not sure what's wrong.
I keep getting "67 items unresolved" and password must match in order to sync. They do match though!
Thanks,
Tom
Click to expand...
Click to collapse
I've had this several times after re-establishing an Activesync partnership. The cure is usually to reset the password on both the desktop and PPC a couple of times until they sync.

Exchange server with invalid certificate

My company runs an exchange server that i can connect to via SLL on the web. However, I always got an invalid certificate message. On 2003 devices on ran certchk and i could synschronize my mail, calender and contacts.
Now - with my JJ - i can not get to my mail anymore because of this invalid certificate. I does not help to download the certificate to my device, since it is invalid.
Is there any reg hack, apps or whatever i can use to overcome this?
Thx
Ronaldovic,
Try exporting the root certificate from the Certificate Authority in "DER" format, copy it to the JJ and run it. This should work as the JJ is not certificate locked.
Ferg.
I did - and when i look in settings-certificates - it shows in the list of certificate but with an enddate of somewhere in 2003 (so it is not valid).
Again, with certchk in 2003 devices it all worked flawlessly.
Are the certificates still be the problem now? Or is it something else?
When i sync, i get an error: 0x80072F17
Ah sorry, I read your mail but didn't really read it and assumed I knew what you were saying.
If you can get a reg editor for the JJ (I use something called "Mobile Registry Editor" which is a PC-based app and works through ActiveSync), change DWORD Value under HKCU\Software\Microsoft\Activesync\Partners\[Secure] to 0 I gather this will do it.
On the point of the certi though, can you not get the CA to issue a new certificate to the Exch box? When connecting through SSL, ActiveSync doesn;t give you a "Yeah connect, I don't care!" dialog box as OWA does.
Ferg.
got a good reg editor, but can not find the last [secure] part...what do u mean by that? For example below ..\partners i see two entries(default) and (ServerNameChanged). and two directories with strange numbers.
About the certificate thing...if i understand u correctly i will never connect if i do not have a valid certificate?
I appreciate the help!!
YEAH!!! Great, got it working, thx to u!
I just love this forum.
Glad to hear it!
I am back....
The sync goes ok now, but every time i send a new mail, it gets send twice. In my outbox on the JJ there is one email, when i receive i see two coming in (exactly the same)
Any1?
i can get it to look like its working by turning off ssl. e.g. it says sycing 20/20 emails. However when i go to messages there are none there! Similarily contacts, tasks and calendar items appear to be syncing in active sync, but they just dont show up!
Hi,
I have run into the same problem.
Used the tips on changing the registry (for which I really thank you!!!).
However, it seemed working until I realize that my Treo 700w keeps asking for the password. No matter how many times I enter my password correctly, it just keeps asking the password over and over again. It does not save my password even if I select "save password" option.
Have you run into this problem and found any workaround?
Thanks in advance. Bo.
Boryu,
Remove and re-add the server source.
I've had this a few times and it's well annoying! This seems to do the trick though.
Ferg.
same issue
i have the same issue,
i used registry editor but its not allowing me to add the reg key!!
am i doing something wrong,, and were do i add the Secure Dword?
Why don't you just renew the certificate? Just right click the website folder within IIS 6.0 and select Properties. There is a security tab (Directory Security?) within which you can renew an existing certificate.
I had the same problem getting push email to work, and renewing the certificate fixed the problem.
Why don't you just renew the certificate? Just right click the website folder within IIS 6.0 and select Properties. There is a security tab (Directory Security?) within which you can renew an existing certificate.
I had the same problem getting push email to work, and renewing the certificate fixed the problem.
ronaldovic said:
got a good reg editor, but can not find the last [secure] part...what do u mean by that? For example below ..\partners i see two entries(default) and (ServerNameChanged). and two directories with strange numbers.
About the certificate thing...if i understand u correctly i will never connect if i do not have a valid certificate?
I appreciate the help!!
Click to expand...
Click to collapse
Hi i see exactly the same, but wich value do i have to change ??
please help
thanks in advance

80072fd Push with SBS2003

My IT guys have been trying to get this push email thing working and it seems to be one difficulty after another and is not as simple as pressing "push email" in the connection icon....
Our latest error appears on my device with the above error code stating
"the security certificate on teh server is invalid. contact your exchange server administrator or ISP to install a valid certificate to the server".
I have read that I need to buy a public certificate from a public authority (CA) or similar such as Verizon or Thawte. Is this the case, or is there a simpler way to get this push email working using the existing configuration and setup of the server?
We use exchange SP2, with outlook 2003 all around. Internet based webmail works correctly with full access, and activesync via PC works perfectly, but push email encounters the above error.
Any suggestions.
are you sure it's 80072fd or 80072efd ?
I don't have a solution, but the problem is described in M$ knowledgebase article: 915438 - see attached Acrobat .PDF.
I had already tried the suggestion in KB915840 to import the certificate from my sbs2k3-domain, but this had failed with "cannot access the certificate" - even with them on the device. However, certificates from my clients' servers, both sbs2k and sbs2k3, import without problems. This happened both before and after o2's AKU2 ROM update - so AKU2 is not the problem. In addition, I spent Easter *totally* reinstalling sbs2k3 and tested it immediately afterwards. All the sbs2k3/Exch2k3-Sp2 boxes are fully patched. The certificate itself is correct/working, since it works for Outlook Web Access via the web with laptops and even the Exec (Universal).
Whilst sync'ing from the workstation via ActiveStink/USB, if you turn off the SSL requirement the sync suceeeds, but that's obviously not a working solution via the 'Net.
Update:
Just had a thought, and checked the various certificates in a hex-editor. The one from my sbs2k3 box is a completely different format. :? I'll see what I can find out.....
maybe not related, but here's a list of all ActiveSync Server Error Codes: http://blogs.flaphead.dns2go.com/archive/2005/11/21/3202.aspx
80072f0d
Sorry, the correct code is 80072f0d.
I know your pains astage, but there is no way we are pulling the box down and putting it back up again, our server hosts 30 + staff simultaneously and I cant take it down just to fix my one desire to have push email.
But I do find it painful and frustrating that microsoft do not adequately support their own platforms and systems dont integrate as they should and as they are promoted.
M$ sks.
Re: 80072f0d
simon_darley said:
....I know your pains astage, but there is no way we are pulling the box down and putting it back up again, our server hosts 30 + staff simultaneously and I cant take it down just to fix my one desire to have push email.....
Click to expand...
Click to collapse
I'm not sure if it was clear from my reply - too tired - but rebuilding the server did not help at all.
Yeh, the pains of rebuilding SBS and having it all configured and running correctly when the staff arrive in the morning is not something I do willingly - hence the use of the holiday. It was done only as a last ditch attempt to solve this and another problem that had Micro$oft totally stumped - not related.
There is a difference in the certificate formats, so that's where I'm concentrating my efforts now. Will let you know what I find.
80072f0d error - the fix!
Just spent the past hour kicking and calling myself an £$%&* idiot.:x
Anyway, to cut the story short, the problem *is* indeed the damn format of the SSL certificate exported by sbs2k3. For the WM5 device to import it, it needs to be in DER X509 format.
If you have imported it into your PC/laptop for OWA/OMA/RWW, then you can easily export it from IE's Internet Options into DER format.
From Internet Options:
- go to Content-tab
- click Certificates-button
- find and highlight your certificate - I had imported mine into Trusted Root Authorities
- click Export-button
- click Next on wizard page
- enable the "DER encoded binary X.509 (.CER)" radio-button, and click Next
- enter a suitable path & filename, e.g.: "myserver.cer"
- click Next, click Finish, click Ok.
- Now copy the certificate to your PDA via ActiveSync.
- Open File Explorer on the PDA,
- Find the certificate file and launch it.
- click Yes to import it and you're done!
I think the reason why my sbs2000 certificates worked was that I had installed Certificate Services on those boxes and exported those certificate from there. I don't understand why some of my client's sbs2003 certificates were in DER-format, and others weren't, but we are talking about Microsoft software, so what else should I expect......
msfp and 80072f0d
After testing a few different certificate variations, the engineers that maintain our servers was able to send me two alternative certificates, one or bother of them appear to ahve worked effective.
So it imported, and now my active sync works for receiving these emails, now I need to look at these heartbeat pings and find out how I set the periodic checking.
Just wondering, normally if you dial a gprs/3g connection, you pay once, and stay connected all day. Does this now mean that it connects, downloads, disconnects, then 5 minutes later reconnects, downloads, and disconnects, thus paying a much larger reconnect fee everytime?
I am playing with this as a new toy, but I can see the costs are going to go ballistic....
and... perhaps for all those that are already experienced here, how does one send an email that remote wipes the device?
is there a command, or a key word or something that makes the system realise the remote wipe command....
sorry, I know this is off the topic of my original post, but thought you might know.
if not, I can start a new topic....!!!
The certificates that I was given was a server.cer and a root.cer.
If anybody needs to know, I can ask the engineers how they did what they gave me to get it to work.
The remote wipe is done from the sbs2k3 box - or rather the box running Exchange2k3Sp2. Your admin needs to install a small tool that he (Domain Administrator credentials needed) then accesses via IE.
Microsoft has published a new white paper (Feb 2006) that describes the whole procedure - just a shame they missed the need for the certificate to be in DER format. The white paper is: "Deploying Windows Mobile 5.0 with Windows Small Business Server 2003".

TyTN "forgets" personal certificate

I try to get my mails pushed to my TyTN. Thus I enabled the appropriate services on my Exchange 2003 SP2 server, set the user permissioning and so on. I generated an P12 cert with my CA and imported it using p12import.exe on my tytn. I also installed .cer for the domain and for the CA on the mobile device. Thus I was able to sync and push. Now I am facing the following issue:
After successfully syncronizing and pushing for some hours, I regularely get an 0x85030027. Checking my certificate I can see that my p12 is gone. After reimporting it using p12import, i can change the server settings the following way to force an "reinitialisation" of the link between user settings and cert: I delete the "m" in "blabla.dynaccess.com", go forward to login information - the password is gone then - go back to the server, add the "m", go forward adding the password. Sometimes I am than able to sync again, sometimes I get an 0x85010004. In the latter case I must delete the whole server setting - loosing all my mails - and have set it once again.
Dealing with this issue now for several days and beeing unable to find any description or solution in this forum and the web, I kindly ask for any idea which could be considered beeing helpful...
PS.: Sorry for my English - it is not my native tongue ;-)
I use CACert certificate for my email and have imported it using smartphoneaddcert utiltity from Micro$oft.
Copy your certificate into \Storage\root.cer (has to be named like this) and run SPAddCert.exe, hopefully that should work
thanks for the immediate answer. i already installed my root-certificate with no probs. The issue I have is related to the individual cert for the device, generated and signed by my ca, which is trusted by the tytn. This individual one disappears after some syncs?!
I don't experience the same problem ...
I think your method is ok (Jacco in DDSL.NL) have a nice tools to import personal certificate to device...
You may also look : http://www.httpsync.net
Cheers
André
Now I can describe the problem more precise: the personal certificate disappears after every soft reset?!
I have the exact same problem !!!!
When you do a soft reset the personal Certificate disappears.
I can reimport it directly, but I need to hook it up to a PC in order to validate the Certificate.
Is there no other way. This is really annoying when i'm on a trip, and I have to soft reset the device.
Does anyone know hpw this can be done differently.
Thanks
Micman

Categories

Resources