juli·17 年前·議論Attacker controls the length of the message so he can make the padding be only 9 bytes long
juli·17 年前·議論Sites using this vulnerable signing method must add a warning to their documentation.Flickr authentication spec lists ludicorp.com authors,http://www.flickr.com/services/api/auth.spec.html
juli·17 年前·議論MD5 is not the problem here, SHA1 is also vulnerable to the extension attack. They should use HMAC.