Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Sat, 18 May 2013 11:13:50 -0400
From:  <jfoug@....net>
To: john-dev@...ts.openwall.com
Subject: rules reading from user classes in john.conf.  Avoids multiple
 defined characters

This patch will eliminated adding the same character more than one time.  (This patch will NOT apply properly, until after the redo regen-lost-salts patch has been applied)

If this user class line:

[UserClasses]
3 = [A-z0-9m-q]

or

[Regen_Salts_UserClasses]
3 = [A-z0-9a-m]

The a-m would be in there 2 times.  With the patch, each of these would only be included 1 time.  Yes, the above user class values are contrived, but an easy to make mistake. The z likely should have been Z. But a user causing overlap is often easy to do, and the patch avoids this by ignoring adding the character values a 2nd time.

Jim.
[ CONTENT OF TYPE application/octet-stream SKIPPED ]

Powered by blists - more mailing lists

Your e-mail address:

Powered by Openwall GNU/*/Linux - Powered by OpenVZ