Password authentication leaves plaintext password copies in managed memory
还没有人认领这个 Issue。
评估
- 难度
- 5/5
- 预计耗时
- 一周以上
- 新手友好度
- 45/100
- Issue 类型
- 缺陷
- 描述清晰度
- 基本清楚
- 活跃度
- 活跃
- 技术栈
- csharp
调研方向
Start with PasswordAuthenticationMethod.Authenticate and trace the flow through Session.SendMessage(RequestMessagePassword) and Session.SendPacket. Reproduce the memory-dump scenario with a unique test password, then add regression coverage for clearing password storage, serialized request data, and plaintext packet buffers after use.
由索引模型根据 Issue 内容生成。
描述
Description
SSH.NET password authentication appears to leave plaintext password data
in managed memory after authentication has completed.
This was discovered during a penetration test by inspecting a process memory
dump after establishing an SSH connection using password authentication.
There appear to be at least two sources of password residue.
PasswordAuthenticationMethod retains the password
PasswordAuthenticationMethod stores the supplied password internally as a
byte array.
When the string-based API is used, the password must additionally exist as a
System.String. Since System.String is immutable, that copy cannot be
explicitly cleared.
The internal byte[] containing the encoded password also appears to remain
allocated after authentication instead of being zeroed when it is no longer
required.
As a result, the plaintext password can remain recoverable from a process
memory dump after authentication.
Serialized SSH_MSG_USERAUTH_REQUEST remains in memory
Using the byte[] password overload reduces the problem because the caller can
clear its own password buffer.
However, this does not eliminate all plaintext copies.
During password authentication the password is serialized into the
SSH_MSG_USERAUTH_REQUEST message.
The relevant flow appears to be approximately:
PasswordAuthenticationMethod.Authenticate
-> Session.SendMessage(RequestMessagePassword)
-> message serialization
-> Session.SendPacket(...)
The serialized packet contains the password in plaintext before SSH transport
encryption is applied.
After the packet has been encrypted/sent, buffers containing the plaintext
packet do not appear to be explicitly zeroed.
In a process memory dump taken after authentication, we were able to locate a
complete plaintext SSH user authentication request containing the password.
Expected behavior
Sensitive authentication data should have the shortest practical lifetime in
memory.
After password authentication has completed, SSH.NET should explicitly clear
buffers that contain:
- the password stored by PasswordAuthenticationMethod;
- temporary encoded password representations;
- serialized SSH_MSG_USERAUTH_REQUEST payloads containing a password;
- temporary packet/plaintext buffers used before encryption.
For byte arrays/spans this could potentially use Array.Clear,
CryptographicOperations.ZeroMemory, or an equivalent mechanism appropriate
for the supported target frameworks.
The goal is not to guarantee that a password can never exist in plaintext
memory. Password authentication necessarily requires SSH.NET to process the
plaintext password.
The goal is to avoid leaving unnecessary plaintext copies recoverable from a
memory dump after those buffers are no longer required.
Why the byte[] overload alone does not solve this
Applications can avoid keeping a managed System.String by obtaining the
credential through a protected representation and creating a temporary byte[]
for SSH.NET.
The application can zero its own byte[] immediately afterwards.
However, once SSH.NET serializes SSH_MSG_USERAUTH_REQUEST, additional
plaintext copies are created internally. Those copies are outside the
caller's control and therefore cannot be cleared by the application.
Consequently this cannot be fully mitigated by callers of SSH.NET.
Security impact
An attacker or diagnostic process capable of obtaining a process memory dump
after SSH authentication may be able to recover the SSH password even though
authentication has already completed.
This is particularly relevant for long-running applications where SSH
connections are created periodically and credentials should not remain
recoverable for the lifetime of the process.
Environment
Observed with password authentication using Renci.SshNet / SSH.NET.
The same behavior should be reproducible by:
- Connect to an SSH server using password authentication.
- Allow authentication to complete.
- Disconnect and dispose the SSH client.
- Force GC if desired.
- Capture a process memory dump.
- Inspect the dump for the known test password.
A unique test password can be used to make identification unambiguous.
Possible direction
A complete fix probably requires handling this at more than one level.
- Avoid unnecessary conversion of password credentials to System.String.
- Clear PasswordAuthenticationMethod password storage when it is no longer
required. - Clear credential-containing RequestMessagePassword storage when
authentication completes. - Clear plaintext serialization/packet buffers after they have been
encrypted or are otherwise no longer needed. - Add regression tests verifying that sensitive buffers are zeroed after
use where practical.
- 主要语言
- C#
- 星标
- 4.4k
- 派生
- 990
- PR 合并指标
- 30 天内没有已合并 PR
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 没有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
sshnet/SSH.NET 的其他 Issue
-
难度 2/5 1-3 小时 新手友好度 62/100
-
ShellStream.Expect over-discards on undecodable bytes, driving ArrayBuffer.ActiveLength negative未关闭
难度 4/5 3-5 天 新手友好度 52/100
-
难度 3/5 1-2 天 新手友好度 68/100
-
难度 4/5 3-5 天 新手友好度 48/100
-
难度 3/5 1-2 天 新手友好度 67/100
相似的 Issue
-
[Bug]: Missing extensions in Agent Card capabilities in v0.3 compat mode可能已有人在做 @hwanders 今天认领。 未关闭
难度 2/5 1-3 小时 新手友好度 84/100
a2aproject/a2a-dotnet#514 · 1 条评论 ·
维护者通常 2 天内回复
-
agentic-workflows untriaged
难度 2/5 1-3 小时 新手友好度 82/100
维护者通常 1 天内回复
-
VS Code
难度 2/5 1-3 小时 新手友好度 65/100
AlamoEngine-Tools/pg-starwarsgame-lsp#207 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 76/100
elsa-workflows/elsa-core#8593 ·
维护者通常 1 天内回复
-
untriaged
难度 2/5 1-3 小时 新手友好度 78/100