HelloZeroNet / HelloZeroNet/ZeroNet

[security] Please add --tor_control_method command line option to allow use of control socket

Ouverte
#1,083 0 commentaires 0 réactions 0 personnes assignées Voir sur GitHub
Langage dominant
JavaScript
Étoiles
18.8k
Forks
2.3k
Métriques de merge des PR
Aucune PR mergée en 30 j

Description

Currently, ```--tor=always``` implies the use of control port (9051 by default). Tor control port is less secure in that it by default allows empty authentication.

Please implement:
```
self.parser.add_argument('--tor_control_method', help='Tor control method', metavar='tor:control_method', default='control-port')
```
with possible values {control-port|control-socket}

```--tor_controller``` then will be dependent on ```--tor_control_method```. In case of ```--tor_control_method=control-port```, it will be an IP host/port with default='127.0.0.1:9051', and for ```--tor_control_method=control-socket``` it will be a file name with the default corresponding to Tor's default control socket location.

In case of ```--tor_control_method=control-socket```, ZeroNet will use control socket and authentication cookie on disk. It will have to be run with _tor group in order to have access to the authentication cookie.

It is more secure to not require control port, and to use control socket with authentication cookie.

Guide de contribution

Aucun guide de contribution indexé pour ce dépôt

Piste de recherche

Start at the command-line parser entry point containing self.parser.add_argument and trace the existing --tor_controller handling. Verify the two documented methods, their defaults, and the control-socket authentication-cookie behavior, then confirm that --tor=always uses the selected method.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Évaluation

Stack technique
python
Domaine
cli, security
Type d'issue
Fonctionnalité
Difficulté
4/5
Temps estimé
3-5 jours
Activité
À l'abandon
Clarté
Plutôt claire
Accessibilité débutants
35/100

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.