|
Message-ID: <20120628202447.GA24988@openwall.com> Date: Fri, 29 Jun 2012 00:24:47 +0400 From: Solar Designer <solar@...nwall.com> To: john-dev@...ts.openwall.com Subject: Re: WPA-PSK big-endian fix Lukas - On Fri, Jun 29, 2012 at 12:12:08AM +0400, Solar Designer wrote: > The attached patch makes the WPA-PSK format (CPU) work on big-endian BTW, perhaps eapol_size and keyver should be validated in valid() and in hccap2john.c. Do these come from an external tool? Or even directly from network traffic? In the latter case, we might even have a remote arbitrary code execution vulnerability here. %-) Also, is it specified (where?) that these are in little-endian form, or does this vary between builds of whatever tool creates the file? Alexander
Powered by blists - more mailing lists
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.