Uploaded image for project: 'MariaDB Connector/J'
  1. MariaDB Connector/J
  2. CONJ-1337

Limit parsec authentication PBKDF2 iteration factor to the connection time

    XMLWordPrintable

Details

    Description

      ParsecPasswordPlugin accepts the PBKDF2 iteration factor from the server's ext-salt response, capped at 20. The factor is an exponent (effective work is 1024 << iterations, so 20 means ~1.07 billion PBKDF2-HMAC-SHA512 rounds, measured at ~13.4 min on an i9-11900K / OpenJDK 25).

      The client performs this work before authentication completes, and since it is pure computation with no intervening socket read, no timeout interrupts it. A malicious or MITM server pins a client core for minutes with a 20 iterations request.

      Fix: derive the cap from the connection time budget instead of hardcoding:
      budget = connectTimeout > 0 ? connectTimeout : SERVER_CONNECT_TIMEOUT_DEFAULT (10s)
      maxIterationFactor = max(0, floor(log2(PBKDF2_ROUNDS_PER_MS * budget / 1024)))

      PBKDF2_ROUNDS_PER_MS is a deliberately conservative throughput constant (262144 rounds / 225 ms)

      connectTimeout	cap	work at cap
      100 ms	6	48 ms
      2500 ms	11	1.5 s
      10 s	13	6.2 s
      30 s	15	25.7 s
      unset/0	13	6.2 s
      

      The bound scales with connectTimeout by design: the client declares its own budget, and a longer declared budget permits a larger factor.

      thanks fg0x0 for reporting it.

      Attachments

        Activity

          People

            diego dupin Diego Dupin
            diego dupin Diego Dupin
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Git Integration

                Error rendering 'com.xiplink.jira.git.jira_git_plugin:git-issue-webpanel'. Please contact your Jira administrators.