janvanderwalt / winauth Goto Github PK
View Code? Open in Web Editor NEWAutomatically exported from code.google.com/p/winauth
Automatically exported from code.google.com/p/winauth
[deleted issue]
the auto join doesnt work in windows authenticator, he lost some first digits
Original issue reported on code.google.com by [email protected]
on 22 Sep 2010 at 1:23
This is actually a major flaw with the original Blizzard Java version as well
(have not checked the iPhone version due to time constraints). Since they
decided to ignore the reasonable disclosure notice, I see fit to publicly
disclose the vulnerability.
Description:
https://docs.google.com/document/edit?id=1pf-YCgUnxR4duE8tr-xulE3rJ1Hw-Bm5aMk5tN
OGU3E&hl=en
Proof of concept:
https://docs.google.com/document/edit?id=1pf-YCgUnxR4duE8tr-xulE3rJ1Hw-Bm5aMk5tN
OGU3E&hl=en
The proof of concept code will not work vs your C# application due to a
different PRNG than java.util.Random, but since the algorithm they use is
fairly easy to reproduce extending the code is trivial (Google yields "The
current implementation of the Random class is based on Donald E. Knuth's
subtractive random number generator algorithm." per MSDN). I would recommend
patching the vulnerability.
The trivial solution: Use System.Security.Cryptography.RNGCryptoServiceProvider
instead of Random in Authenticator.CreateInitializationRandom()
Other things that you *should* do: Randomize the model number to armor the
Initialization Request.
Best regards.
Original issue reported on code.google.com by [email protected]
on 20 Sep 2010 at 5:37
I fear I shall be bashed, but I ran both the mobile version as well as the
desktop version version of your authenticator, and I find it odd that one
cannot use both at the same time for one account, as it appears to be
impossible to copy the settings from one to the other.
The mobile version can only import old Java settings, while the desktop version
can't export to such a format. If all the information it provides (via the
unencrypted XML file) are enough to create such a .db file for the mobile
version, it is still unclear what kind of structure this file should have.
...please don't bash me -.- ...
Original issue reported on code.google.com by [email protected]
on 5 Oct 2010 at 10:27
A declarative, efficient, and flexible JavaScript library for building user interfaces.
๐ Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
An Open Source Machine Learning Framework for Everyone
The Web framework for perfectionists with deadlines.
A PHP framework for web artisans
Bring data to life with SVG, Canvas and HTML. ๐๐๐
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
Some thing interesting about web. New door for the world.
A server is a program made to process requests and deliver data to clients.
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
Some thing interesting about visualization, use data art
Some thing interesting about game, make everyone happy.
We are working to build community through open source technology. NB: members must have two-factor auth.
Open source projects and samples from Microsoft.
Google โค๏ธ Open Source for everyone.
Alibaba Open Source for everyone
Data-Driven Documents codes.
China tencent open source team.