Browse Source

Fix incorrect IV usage which slightly reduced security

pull/2740/head
Shelikhoo 4 years ago
parent
commit
e2e266114a
No known key found for this signature in database
GPG Key ID: C4D5E79D22B25316
  1. 2
      proxy/vmess/encoding/client.go
  2. 2
      proxy/vmess/encoding/server.go

2
proxy/vmess/encoding/client.go

@ -71,7 +71,7 @@ func NewClientSession(idHash protocol.IDHash, ctx context.Context) *ClientSessio
} else {
BodyKey := sha256.Sum256(session.requestBodyKey[:])
copy(session.responseBodyKey[:], BodyKey[:16])
BodyIV := sha256.Sum256(session.requestBodyKey[:])
BodyIV := sha256.Sum256(session.requestBodyIV[:])
copy(session.responseBodyIV[:], BodyIV[:16])
}

2
proxy/vmess/encoding/server.go

@ -374,7 +374,7 @@ func (s *ServerSession) EncodeResponseHeader(header *protocol.ResponseHeader, wr
} else {
BodyKey := sha256.Sum256(s.requestBodyKey[:])
copy(s.responseBodyKey[:], BodyKey[:16])
BodyIV := sha256.Sum256(s.requestBodyKey[:])
BodyIV := sha256.Sum256(s.requestBodyIV[:])
copy(s.responseBodyIV[:], BodyIV[:16])
}

Loading…
Cancel
Save