« Intergraph, patents, and licensing | Main | Multithreading and CAD »

Security Flaw in AutoCAD 2007 Password Protection

In the process of working on reverse-engineering AutoCAD 2007's DWG file format, the Open Design Alliance has discovered what appears to be a serious security flaw. Although I've reported this flaw to Autodesk management twice since I became aware of it (and both times suggested that it would be more appropriate if they disclosed it than if the Open Design Alliance did), I received no response.

Since this flaw creates a potentially serious security vulnerability for customer data, I'm reporting it here.

Starting with the 2004 version, AutoCAD has supported high-security password-protection of DWG files. When a password is added to a DWG file, AutoCAD uses the password as a key to lock the file using the encryption API provided by Microsoft Windows.

The 2007 version of AutoCAD supports the same password protection scheme -- except that, in our testing, it fails to actually lock (encrypt) the file.

AutoCAD 2007 will still not open a password protected DWG file without the password being entered, so a user may mistakenly believe that their data is secure -- yet it is a trivial matter for a knowledgable person to gain full access to the DWG file, without knowing the password.

We are continuing to investigate, and may be able to find a fix for this problem -- however, without Autodesk's cooperation (which we'd welcome), what we can do is greatly limited because of restrictive terms in the AutoCAD EULA.

Posted on Wednesday, June 28, 2006 at 02:06PM by Registered CommenterEvan Yares in | Comments2 Comments

Reader Comments (2)

I to have a problem with autocad 2007 password protection. When i try to make a dwg password protected i can not. I get to the point were i enter the password but when i press the OK button it wont do anything. do you know the work around for this?
September 24, 2007 | Unregistered CommenterAnthony
I have forgotten the password of my dwg file. Is there any way to recover the password or file.....
March 2, 2009 | Unregistered CommenterMadan Saini

PostPost a New Comment

Enter your information below to add a new comment.

My response is on my own website »
Author Email (optional):
Author URL (optional):
Post:
 
All HTML will be escaped. Hyperlinks will be created for URLs automatically.