mirror of
https://github.com/myvesta/vesta
synced 2025-08-14 10:37:42 -07:00
Timing attack fix from security experts https://arcturussecurity.com
This commit is contained in:
parent
67a0e8d108
commit
5f68c1b634
1 changed files with 1 additions and 1 deletions
|
@ -48,7 +48,7 @@ if ((!empty($_POST['user'])) && (!empty($_POST['code'])) && (!empty($_POST['pass
|
|||
if ( $return_var == 0 ) {
|
||||
$data = json_decode(implode('', $output), true);
|
||||
$rkey = $data[$user]['RKEY'];
|
||||
if ($rkey == $_POST['code']) {
|
||||
if (hash_equals($rkey, $POST[‘code’])) {
|
||||
$v_password = tempnam("/tmp","vst");
|
||||
$fp = fopen($v_password, "w");
|
||||
fwrite($fp, $_POST['password']."\n");
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue