~kennylevinsen/greetd-devel

1

Plaintext passwords potentially being exposed through format macro

Details
Message ID
<d379e2af-5eb6-4d0f-9a3b-88f5f305c599@yahoo.com>
DKIM signature
permerror
Download raw message
If a client incorrectly communicates with the session worker, then it's
possible for plaintext passwords to be displayed.

This error appeared for me when I was testing tuigreet with
fprintd-grosshack, which in some situations seems to cause the greeter
to incorrectly return a "PamResponse" when the worker expects a response
in the form of either "Args" or "Cancel". Since unexpected messages are
returned as an error using the format! macro, this returns an error
message that directly exposes the user's password in plaintext.
Details
Message ID
<17775f69-5678-4002-8387-127bd3391d7b@kl.wtf>
In-Reply-To
<d379e2af-5eb6-4d0f-9a3b-88f5f305c599@yahoo.com> (view parent)
DKIM signature
pass
Download raw message
On 4/27/24 11:55 PM, Nathaniel Mason wrote:
> If a client incorrectly communicates with the session worker, then it's
> possible for plaintext passwords to be displayed.
>
> This error appeared for me when I was testing tuigreet with
> fprintd-grosshack, which in some situations seems to cause the greeter
> to incorrectly return a "PamResponse" when the worker expects a response
> in the form of either "Args" or "Cancel". Since unexpected messages are
> returned as an error using the format! macro, this returns an error
> message that directly exposes the user's password in plaintext.


There is a bug in the greeter if it sends a 
Request::PostAuthMessageResponse in response to anything other than 
Response::AuthMessage. The case you describe is hit if such request is 
sent after having received Response::Success.

It might make sense to send a hard error in this case.
Reply to thread Export thread (mbox)