cipher_test.go 3.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130
  1. // Copyright 2011 The Go Authors. All rights reserved.
  2. // Use of this source code is governed by a BSD-style
  3. // license that can be found in the LICENSE file.
  4. package ssh
  5. import (
  6. "bytes"
  7. "crypto"
  8. "crypto/aes"
  9. "crypto/rand"
  10. "testing"
  11. )
  12. func TestDefaultCiphersExist(t *testing.T) {
  13. for _, cipherAlgo := range supportedCiphers {
  14. if _, ok := cipherModes[cipherAlgo]; !ok {
  15. t.Errorf("default cipher %q is unknown", cipherAlgo)
  16. }
  17. }
  18. }
  19. func TestPacketCiphers(t *testing.T) {
  20. defaultMac := "hmac-sha2-256"
  21. defaultCipher := "aes128-ctr"
  22. for cipher := range cipherModes {
  23. t.Run("cipher="+cipher,
  24. func(t *testing.T) { testPacketCipher(t, cipher, defaultMac) })
  25. }
  26. for mac := range macModes {
  27. t.Run("mac="+mac,
  28. func(t *testing.T) { testPacketCipher(t, defaultCipher, mac) })
  29. }
  30. }
  31. func testPacketCipher(t *testing.T, cipher, mac string) {
  32. kr := &kexResult{Hash: crypto.SHA1}
  33. algs := directionAlgorithms{
  34. Cipher: cipher,
  35. MAC: mac,
  36. Compression: "none",
  37. }
  38. client, err := newPacketCipher(clientKeys, algs, kr)
  39. if err != nil {
  40. t.Fatalf("newPacketCipher(client, %q, %q): %v", cipher, mac, err)
  41. }
  42. server, err := newPacketCipher(clientKeys, algs, kr)
  43. if err != nil {
  44. t.Fatalf("newPacketCipher(client, %q, %q): %v", cipher, mac, err)
  45. }
  46. want := "bla bla"
  47. input := []byte(want)
  48. buf := &bytes.Buffer{}
  49. if err := client.writePacket(0, buf, rand.Reader, input); err != nil {
  50. t.Fatalf("writePacket(%q, %q): %v", cipher, mac, err)
  51. }
  52. packet, err := server.readPacket(0, buf)
  53. if err != nil {
  54. t.Fatalf("readPacket(%q, %q): %v", cipher, mac, err)
  55. }
  56. if string(packet) != want {
  57. t.Errorf("roundtrip(%q, %q): got %q, want %q", cipher, mac, packet, want)
  58. }
  59. }
  60. func TestCBCOracleCounterMeasure(t *testing.T) {
  61. cipherModes[aes128cbcID] = &streamCipherMode{16, aes.BlockSize, 0, nil}
  62. defer delete(cipherModes, aes128cbcID)
  63. kr := &kexResult{Hash: crypto.SHA1}
  64. algs := directionAlgorithms{
  65. Cipher: aes128cbcID,
  66. MAC: "hmac-sha1",
  67. Compression: "none",
  68. }
  69. client, err := newPacketCipher(clientKeys, algs, kr)
  70. if err != nil {
  71. t.Fatalf("newPacketCipher(client): %v", err)
  72. }
  73. want := "bla bla"
  74. input := []byte(want)
  75. buf := &bytes.Buffer{}
  76. if err := client.writePacket(0, buf, rand.Reader, input); err != nil {
  77. t.Errorf("writePacket: %v", err)
  78. }
  79. packetSize := buf.Len()
  80. buf.Write(make([]byte, 2*maxPacket))
  81. // We corrupt each byte, but this usually will only test the
  82. // 'packet too large' or 'MAC failure' cases.
  83. lastRead := -1
  84. for i := 0; i < packetSize; i++ {
  85. server, err := newPacketCipher(clientKeys, algs, kr)
  86. if err != nil {
  87. t.Fatalf("newPacketCipher(client): %v", err)
  88. }
  89. fresh := &bytes.Buffer{}
  90. fresh.Write(buf.Bytes())
  91. fresh.Bytes()[i] ^= 0x01
  92. before := fresh.Len()
  93. _, err = server.readPacket(0, fresh)
  94. if err == nil {
  95. t.Errorf("corrupt byte %d: readPacket succeeded ", i)
  96. continue
  97. }
  98. if _, ok := err.(cbcError); !ok {
  99. t.Errorf("corrupt byte %d: got %v (%T), want cbcError", i, err, err)
  100. continue
  101. }
  102. after := fresh.Len()
  103. bytesRead := before - after
  104. if bytesRead < maxPacket {
  105. t.Errorf("corrupt byte %d: read %d bytes, want more than %d", i, bytesRead, maxPacket)
  106. continue
  107. }
  108. if i > 0 && bytesRead != lastRead {
  109. t.Errorf("corrupt byte %d: read %d bytes, want %d bytes read", i, bytesRead, lastRead)
  110. }
  111. lastRead = bytesRead
  112. }
  113. }