Skip to content

fix: decode password messages according to the requested auth type - #1211

Open
v0idpwn wants to merge 3 commits into
mainfrom
fix/md5-start
Open

v0idpwn wants to merge 3 commits into
mainfrom
fix/md5-start

Conversation

@v0idpwn

@v0idpwn v0idpwn commented Sep 26, 2026

Copy link
Copy Markdown
Member

PasswordMessage, SASLInitialResponse and SASLResponse share the 'p' tag, and their contents can only be interpreted knowing which one was requested. Server.decode_pkt/1 guessed from the contents, so a cleartext password starting with "md5" was decoded as an MD5 digest and rejected.

Add Server.decode_password_message/2, which takes the expected message type, and use it in the password, JIT and SCRAM auth methods.

PasswordMessage, SASLInitialResponse and SASLResponse share the 'p' tag,
and their contents can only be interpreted knowing which one was
requested. Server.decode_pkt/1 guessed from the contents, so a cleartext
password starting with "md5" was decoded as an MD5 digest and rejected.

Add Server.decode_password_message/2, which takes the expected message
type, and use it in the password, JIT and SCRAM auth methods.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant