Skip to content

Fixed pass-the-hash vulnerability#11

Open
phantom-voltage wants to merge 3 commits intopaxed:masterfrom
phantom-voltage:master
Open

Fixed pass-the-hash vulnerability#11
phantom-voltage wants to merge 3 commits intopaxed:masterfrom
phantom-voltage:master

Conversation

@phantom-voltage
Copy link
Copy Markdown

@phantom-voltage phantom-voltage commented May 13, 2017

In reference to #10, I fixed the pass-the-hash vulnerability.

The vulnerability was tested before and after I made changes using matsuu's docker image for a Nethack server. Using the hash as the password did not log me in once the ifdefs were added.

I added ifdefs, because flat password storing appears to be only used if SQLITE3 is not enabled.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant