mirror of https://github.com/wolfSSL/wolfssh.git
examples/portfwd: drop the password from the options banner
- The startup banner's password line and its argument are dropped from the printf; ssh host, username and the two forward endpoints remain. - userPassword has internal linkage, and portfwd_worker() zeroes it with wc_ForceZero() as soon as wolfSSH_connect() returns, on both the success and the failure path. - portfwd.c includes wolfssl/wolfcrypt/memory.h. Issue: F-11673pull/1171/head
parent
709352ba8b
commit
8e8b62d358
|
|
@ -44,6 +44,7 @@
|
|||
#include <wolfssh/test.h>
|
||||
#include <wolfssh/port.h>
|
||||
#include <wolfssl/wolfcrypt/ecc.h>
|
||||
#include <wolfssl/wolfcrypt/memory.h>
|
||||
|
||||
#ifndef NO_WOLFSSH_CLIENT
|
||||
#include "examples/portfwd/wolfssh_portfwd.h"
|
||||
|
|
@ -181,7 +182,7 @@ static int SetEcho(int on)
|
|||
}
|
||||
|
||||
|
||||
byte userPassword[256];
|
||||
static byte userPassword[256];
|
||||
|
||||
|
||||
static int wsUserAuth(byte authType,
|
||||
|
|
@ -535,10 +536,9 @@ THREAD_RETURN WOLFSSH_THREAD portfwd_worker(void* args)
|
|||
printf("portfwd options\n"
|
||||
" * ssh host: %s:%u\n"
|
||||
" * username: %s\n"
|
||||
" * password: %s\n"
|
||||
" * forward from: %s:%u\n"
|
||||
" * forward to: %s:%u\n",
|
||||
host, port, username, password ? password : "",
|
||||
host, port, username,
|
||||
fwdFromHost, fwdFromPort,
|
||||
fwdToHost, fwdToPort);
|
||||
|
||||
|
|
@ -622,6 +622,8 @@ THREAD_RETURN WOLFSSH_THREAD portfwd_worker(void* args)
|
|||
err_sys("Couldn't set the session's socket.");
|
||||
|
||||
ret = wolfSSH_connect(ssh);
|
||||
/* User authentication is done with the buffer either way. */
|
||||
wc_ForceZero(userPassword, sizeof(userPassword));
|
||||
if (ret != WS_SUCCESS)
|
||||
err_sys("Couldn't connect SFTP");
|
||||
|
||||
|
|
|
|||
Loading…
Reference in New Issue