A worm/trojan wouldn't even have to do that, but I doubt one would be able to do that via automation. When not using the Application Password Protection passwords are stored in the flashfxp.ini using a generic encryption and all you need to do is figure out the algorithm.
Using Application Password Protection is a 100% solution, not using it you are at risk no matter how you look at it.
You would not believe how many people have contacted me asking for the reveal password feature to be available even when the Application Password is not set.
|