|
Message-ID: <20030330115708.GB12313@openwall.com> Date: Sun, 30 Mar 2003 15:57:08 +0400 From: Solar Designer <solar@...nwall.com> To: popa3d-users@...ts.openwall.com Subject: Re: virtual.c another question On Sun, Mar 30, 2003 at 05:18:05PM +0600, Boris Kovalenko wrote: > Solar Designer wrote: > >On Sun, Mar 30, 2003 at 01:29:38PM +0600, Boris Kovalenko wrote: > >>Why to run other code if we already know that user is invalid? Why lstat > >>directory and try to open file for this "INVALID" user? > > > >This is to reduce information leaks via timing. > > What type of information? It's primarily whether a username corresponds to an existing mail account or not. > May be I need do the same within my module? Very likely so. I'm afraid these discussions on programming topics are of no use to most popa3d-users subscribers. If anyone is annoyed by them, please let me know and I'll be bringing them off-list in the future. -- /sd
Powered by blists - more mailing lists
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.