CWE-316: Plaintext Storage in Memory | Demonstration
This demo shows how we could retrieve senstive data of a program through memory dump. We demonstrated it using a real-world application, pfingo 4.2. Sensitive data should always be encrypted in program memory once they have been pulled from external sources/user inputs. Note that malicious programs could do the same.
http://core.yehg.net/lab/pr0js/training/view/CWE-316_plaintext-storage-in-memory/
http://core.yehg.net/lab/pr0js/training/view/CWE-316_plaintext-storage-in-memory/