fix(remote): 补 ReadVncServerConfig 漏读的 LogLevel(读/写/结构体三处均达 37 项全集)+VncPasswordDecrypt 短于 8 字节直接返回空串(底层 DES 按前 8 字节切片, 短输入必 panic); 新增字段数锁定与短密文防护单测

This commit is contained in:
w11
2026-09-23 19:55:37 +08:00
parent 38e44f7b4a
commit 006138172f
2 changed files with 29 additions and 2 deletions
+6 -1
View File
@@ -40,6 +40,7 @@ func ReadVncServerConfig() (VncServerConfig, error) {
config.RepeatControlAuthentication, _, _ = GetDwordValue(key, "RepeatControlAuthentication")
config.LoopbackOnly, _, _ = GetDwordValue(key, "LoopbackOnly")
config.AcceptHttpConnections, _, _ = GetDwordValue(key, "AcceptHttpConnections")
config.LogLevel, _, _ = GetDwordValue(key, "LogLevel")
config.EnableFileTransfers, _, _ = GetDwordValue(key, "EnableFileTransfers")
config.RemoveWallpaper, _, _ = GetDwordValue(key, "RemoveWallpaper")
config.UseD3D, _, _ = GetDwordValue(key, "UseD3D")
@@ -177,7 +178,11 @@ func VncPasswordCrypt(password string) []byte {
return vncpasswd.Crypt(password)
}
// VncPasswordDecrypt 解密 VNC 密码
// VncPasswordDecrypt 解密 VNC 密码。密文恒为 8 字节(标准 VNC DES),
// 不足 8 字节(缺失/截断)直接返回空串——底层 DES 解密会按前 8 字节切片,短输入必 panic。
func VncPasswordDecrypt(data []byte) string {
if len(data) < 8 {
return ""
}
return vncpasswd.Decrypt(data)
}