Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20120628202447.GA24988@openwall.com>
Date: Fri, 29 Jun 2012 00:24:47 +0400
From: Solar Designer <solar@...nwall.com>
To: john-dev@...ts.openwall.com
Subject: Re: WPA-PSK big-endian fix

Lukas -

On Fri, Jun 29, 2012 at 12:12:08AM +0400, Solar Designer wrote:
> The attached patch makes the WPA-PSK format (CPU) work on big-endian

BTW, perhaps eapol_size and keyver should be validated in valid() and in
hccap2john.c.

Do these come from an external tool?  Or even directly from network
traffic?  In the latter case, we might even have a remote arbitrary code
execution vulnerability here. %-)

Also, is it specified (where?) that these are in little-endian form, or
does this vary between builds of whatever tool creates the file?

Alexander

Powered by blists - more mailing lists

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.