fix(remote): 补 ReadVncServerConfig 漏读的 LogLevel(读/写/结构体三处均达 37 项全集)+VncPasswordDecrypt 短于 8 字节直接返回空串(底层 DES 按前 8 字节切片, 短输入必 panic); 新增字段数锁定与短密文防护单测
This commit is contained in:
+23
-1
@@ -2,7 +2,10 @@
|
||||
|
||||
package remote
|
||||
|
||||
import "testing"
|
||||
import (
|
||||
"reflect"
|
||||
"testing"
|
||||
)
|
||||
|
||||
func TestGetServiceStatusNonExist(t *testing.T) {
|
||||
// 不存在的服务应返回错误(Radmin 服务普通机器上不会安装)
|
||||
@@ -91,3 +94,22 @@ func TestInstallVncServerMissingExe(t *testing.T) {
|
||||
t.Fatal("exe 不存在时应返回错误")
|
||||
}
|
||||
}
|
||||
|
||||
// TestVncServerConfigFieldCount 锁定配置字段总数:必须与本机最新版 TightVNC(2.8.x)
|
||||
// 注册表 SOFTWARE\TightVNC\Server 下的 37 个值一一对应。加/删字段前先核对注册表全集,
|
||||
// 并同步检查 ReadVncServerConfig / WriteVncServerConfig 的逐项覆盖(此前曾漏 LogLevel 写、
|
||||
// ConnectToRdp 误读、LogLevel 漏读, 靠本测试与脚本对账拦截)。
|
||||
func TestVncServerConfigFieldCount(t *testing.T) {
|
||||
if got := reflect.TypeOf(VncServerConfig{}).NumField(); got != 37 {
|
||||
t.Errorf("VncServerConfig 字段数 = %d, want 37(最新版注册表全集)", got)
|
||||
}
|
||||
}
|
||||
|
||||
// TestVncPasswordDecryptShortInput 短于 8 字节的密文(缺失/截断)必须返回空串而非 panic
|
||||
func TestVncPasswordDecryptShortInput(t *testing.T) {
|
||||
for _, data := range [][]byte{nil, {}, []byte("abc"), []byte("1234567")} {
|
||||
if got := VncPasswordDecrypt(data); got != "" {
|
||||
t.Errorf("VncPasswordDecrypt(len=%d) = %q, want 空串且不 panic", len(data), got)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
+6
-1
@@ -40,6 +40,7 @@ func ReadVncServerConfig() (VncServerConfig, error) {
|
||||
config.RepeatControlAuthentication, _, _ = GetDwordValue(key, "RepeatControlAuthentication")
|
||||
config.LoopbackOnly, _, _ = GetDwordValue(key, "LoopbackOnly")
|
||||
config.AcceptHttpConnections, _, _ = GetDwordValue(key, "AcceptHttpConnections")
|
||||
config.LogLevel, _, _ = GetDwordValue(key, "LogLevel")
|
||||
config.EnableFileTransfers, _, _ = GetDwordValue(key, "EnableFileTransfers")
|
||||
config.RemoveWallpaper, _, _ = GetDwordValue(key, "RemoveWallpaper")
|
||||
config.UseD3D, _, _ = GetDwordValue(key, "UseD3D")
|
||||
@@ -177,7 +178,11 @@ func VncPasswordCrypt(password string) []byte {
|
||||
return vncpasswd.Crypt(password)
|
||||
}
|
||||
|
||||
// VncPasswordDecrypt 解密 VNC 密码
|
||||
// VncPasswordDecrypt 解密 VNC 密码。密文恒为 8 字节(标准 VNC DES),
|
||||
// 不足 8 字节(缺失/截断)直接返回空串——底层 DES 解密会按前 8 字节切片,短输入必 panic。
|
||||
func VncPasswordDecrypt(data []byte) string {
|
||||
if len(data) < 8 {
|
||||
return ""
|
||||
}
|
||||
return vncpasswd.Decrypt(data)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user