Post from wezm on 05 Dec 2019

This is a static archive of wezm@decentralised.social

https://mastodon.decentralised.social/@wezm is now my primary account

☜ Back to home page
wezm

OpenBSD login vulnerability that allows you to trivially bypass password. Has been there for some 18 odd years.

TL;DR didn’t sanitize usernames which could contain “-“ making them parse as options to the authentication program. Exploiting this, username “-schallenge:passwd” allowed silent auth bypass because the passwd backend doesn’t require a challenge.

https://www.openwall.com/lists/oss-security/2019/12/04/5