An empty password will pass this check because the code uses the length of the user entry, not the length of the correct password. Other potential problems (buffer overflows, etc.) are left as an exercise for the reader. [Shameless plug: If you enjoy problems like this, have strong security experience, communicate well, and want a job at a fun (and profitable) company, visit http://www.cryptography.com/company/careers.html.]
10) Re:fhnlsfdlkm&5nlkd%Bvbcvbc by Anonymous Coward
Didn't Windows 95 networking have a flaw along these lines? It sounds pretty familiar, and I remember thinking at the time that it was astonishing that such a bug wasn't noticed until years after it was introduced...
ROT13 Translation (Score:1)
10) Re:fhnlsfdlkm&5nlkd%Bvbcvbc
by Anonymous Coward
0rrsn Hi, I'm wondering if
Re:ROT13 Translation (Score:2)