Skip to content

Commit 0d278f6

Browse files
ahmed-farid-devsmowton
authored andcommitted
Create Test.java
1 parent 1bc5fe1 commit 0d278f6

File tree

1 file changed

+19
-0
lines changed
  • java/ql/test/experimental/query-tests/security/CWE-208/TimingAttackAgainstHeader

1 file changed

+19
-0
lines changed
Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,19 @@
1+
import javax.servlet.http.HttpServletRequest;
2+
import java.nio.charset.StandardCharsets;
3+
import java.security.MessageDigest;
4+
import java.lang.String;
5+
6+
7+
public class Test {
8+
private boolean UnsafeComparison(HttpServletRequest request) {
9+
String Key = "secret";
10+
return Key.equals(request.getHeader("X-Auth-Token"));
11+
}
12+
13+
private boolean safeComparison(HttpServletRequest request) {
14+
String token = request.getHeader("X-Auth-Token");
15+
String Key = "secret";
16+
return MessageDigest.isEqual(Key.getBytes(StandardCharsets.UTF_8), token.getBytes(StandardCharsets.UTF_8));
17+
}
18+
19+
}

0 commit comments

Comments
 (0)