Limiting The Exposure of Plain Text Passwords in C#
netspi.com | 博客 | #pentesting | #secure-coding | #thick-client | #dotnet | #csharp | #securestring | #memory-exposure
摘要
NetSPI 剖析 .NET 厚客户端应用中明文密码在内存暴露的问题:即使使用 SecureString,NetworkCredential 在发送 WebRequest 时仍会通过 InternalGetPassword 还原明文密码。作者建议改用可变的字符/字节数组并固定内存位置,给出更安全的登录实现代码。
- 发布时间
- 收录时间
Skip to content