Skip to content

dgamelaunch vulnerable to pass-the-hash attack #10

@adamreiser

Description

@adamreiser

The passwordgood function returns the same result, successful authentication, if the cpw parameter is the plaintext password or the password hash. I'm guessing that pre-git dgamelaunch didn't hash passwords at all, and this check was retained for compatiblity. Unfortunately, this means that the user database/file effectively stores cleartext passwords for the purposes of logging into dgamelaunch.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions