安裝中文字典英文字典辭典工具!
安裝中文字典英文字典辭典工具!
|
- String Comparison Timing Attack in Plain English
Now I can do the same trick with "caaaaaaa", "cbbbbbbb", etc Cracking one letter at a time is HUGELY faster than cracking the whole password at a time This "lazy" string comparison is generally a good thing for programmers because it makes things run faster, but it's bad for security
|
|
|