Skip to content

Commit

Permalink
fix use of uninitialized username_value and password_value variables
Browse files Browse the repository at this point in the history
  • Loading branch information
mmguero committed Feb 17, 2022
1 parent 697e131 commit b2bcba7
Showing 1 changed file with 4 additions and 2 deletions.
6 changes: 4 additions & 2 deletions scripts/main.zeek
Original file line number Diff line number Diff line change
Expand Up @@ -100,15 +100,17 @@ event http_message_done(c: connection, is_orig: bool, stat: http_message_stat)
{
local post_parsed = split_string(c$sp$post_data, /&/);
local password_seen = F;
local username_value = "";
local password_value = "";

for (p in post_parsed) {
local kv = split_string1(post_parsed[p], /=/);
if (to_upper(kv[0]) in username_fields) {
local username_value = kv[1];
username_value = kv[1];
c$http$post_username = username_value;
}
if (to_upper(kv[0]) in password_fields) {
local password_value = kv[1];
password_value = kv[1];
password_seen = T;

if ( log_password_plaintext )
Expand Down

0 comments on commit b2bcba7

Please sign in to comment.