Skip to content

Verify S7CommPlus V3 and legacy response HMACs #832

Description

@gijzelaerr

Problem

For authenticated traffic, the client calculates HMAC-SHA256 for outgoing requests. Incoming responses merely have their hash-length byte and digest stripped and logged; the digest is never verified.

A corrupted, incorrectly keyed or tampered response is therefore accepted as valid application data. Fragment reassembly and Explore continuation handling also strip authenticated prefixes without verification.

Scope

  • Verify response digests with constant-time comparison before parsing application data.
  • Cover single-frame responses and all fragment/reassembly paths.
  • Implement the legacy first-fragment/cumulative digest semantics used by compatible implementations.
  • Raise a dedicated, actionable S7CommPlus integrity error on mismatch.
  • Add deterministic valid, wrong-key, modified-payload, truncated-digest and fragmented-response tests.

Server-side generation is related to #803, but client verification should be independently testable with captured/golden frames.

Acceptance criteria

  • No authenticated response reaches a payload parser before successful digest verification.
  • Any changed digest-covered byte causes a deterministic exception and invalidates the connection.
  • Invalid digest length and truncated frames are rejected.
  • Valid multi-fragment responses still reassemble correctly.
  • Comparison uses hmac.compare_digest or an equivalent constant-time primitive.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions