From b940077553a538a14519bd11207c96bfd7b5ae4e Mon Sep 17 00:00:00 2001 From: Adam Date: Thu, 16 Oct 2014 21:38:46 -0400 Subject: Validate credentials sent via sasl more --- modules/extra/m_sasl_dh-blowfish.cpp | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) (limited to 'modules/extra/m_sasl_dh-blowfish.cpp') diff --git a/modules/extra/m_sasl_dh-blowfish.cpp b/modules/extra/m_sasl_dh-blowfish.cpp index df55f06ea..c665b5b5f 100644 --- a/modules/extra/m_sasl_dh-blowfish.cpp +++ b/modules/extra/m_sasl_dh-blowfish.cpp @@ -152,7 +152,7 @@ class DHBS : public Mechanism const Anope::string username = reinterpret_cast(&data[pos]); // Check that the username is valid, and that we have at least one block of data // 2 + 1 + 8 = uint16_t size for keylen, \0 for username, 8 for one block of data - if (username.empty() || username.length() + keysize + 2 + 1 + 8 > decodedlen) + if (username.empty() || username.length() + keysize + 2 + 1 + 8 > decodedlen || !IRCD->IsNickValid(username)) return Err(sess, pubkey); pos += username.length() + 1; @@ -167,7 +167,7 @@ class DHBS : public Mechanism BF_ecb_encrypt(&data[pos + i], reinterpret_cast(&decrypted[i]), &BFKey, BF_DECRYPT); std::string password = &decrypted[0]; - if (password.empty()) + if (password.empty() || password.find_first_of("\r\n") != Anope::string::npos) return Err(sess, pubkey); SASL::IdentifyRequest* req = new SASL::IdentifyRequest(this->owner, m.source, username, password); -- cgit