|
|
Log in / Subscribe / Register

Seemingly crazy...

Seemingly crazy...

Posted Sep 11, 2015 9:04 UTC (Fri) by jem (subscriber, #24231)
In reply to: Seemingly crazy... by kschendel
Parent article: User-space page fault handling

This reminds me of the old password checking flaw in TOPS-20. The "login" (or equivalent) system was passed a user space buffer as parameter, from which it read the password one character at a time. Once it got an incorrect character, it stopped and returned "incorrect password". The trick was to place the password at a page boundary, so that one part of it was at the end of page N and the next part continued at the start of page N+1. If you got a page fault, you knew that the characters on page N were correct. This significantly reduced the amount of work to crack the password by brute force.


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds