Bypassing strncmp was particularly insightful.
Bypassing strncmp was particularly insightful.
The "strncmp(saved_pwd,pass0,strlen(pass0))" looks equally bad. Probably someone did not understood the advice "always check the length first" and just did it everywhere.
Intel AMT checked the password in a similar way some time ago: https://www.tenable.com/blog/rediscovering-the-intel-amt-vul...
I often remember my PHP days in horror, but mysqli_query manpage does warn you about SQL-injections now.
"The strncmp() function is similar, except it compares only the first (at most) n bytes of s1 and s2."
Possibly it's years of string wrangling in C that sets me up here for being biased towards the compact way in which the C manpages state what the function will do, but 'early termination' because of zero length strings for comparisions returns 0 just as sure as comparing "" and "" would. And that 0 indicates a match...
I'm definitely not arguing that C shouldn't be used and everybody should be using <insert-the-currently-trendy-systems-programming-language>: just thinking out loud if improved documentation could prevent at least some of the common footguns.
Scopes have massive amounts of true random data at their disposal. :P
This isn't a nonce where you might need some kind of special timing properties.
We hash so that people can't grab your password and use it elsewhere. We add some salt to make the hash more robust to memory and precomputation attacks.